Courseiva
IT Risk Assessment →mediumMultiple Choice

CRISC IT Risk Assessment Practice Question

A risk analyst is preparing a risk register for a new customer relationship management (CRM) system hosted in a public cloud. For each identified risk, the analyst assigns a likelihood rating (1–5) and an impact rating (1–5) based on team consensus, and then multiplies the two scores to produce a risk score. Which risk assessment approach is the analyst using?

⚠ Common exam trap

The trap here is assuming that any method producing numbers is automatically quantitative, when ordinal consensus ratings multiplied together remain semi-quantitative.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Semi-quantitative risk analysis

Multiplying ordinal likelihood and impact ratings generates a relative risk score, which is characteristic of semi-quantitative analysis. The ratings originate from expert consensus rather than measured frequencies or financial values, so the result is not a true quantitative loss estimate, and it is more structured than a purely qualitative high/medium/low label.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Semi-quantitative risk analysis

    Why this is correct

    This is correct because semi-quantitative analysis uses numeric rating scales for likelihood and impact but the values are derived from qualitative judgments rather than measured frequencies or monetary losses. Multiplying ordinal ratings produces a relative risk score that supports ranking and prioritization, which matches the analyst's use of consensus-based 1–5 ratings for the CRM system.

  • ✗

    Quantitative risk analysis

    Why it's wrong here

    Quantitative analysis requires measurable inputs such as annualized rate of occurrence, asset value, and exposure factor to calculate monetary loss expectancy. Here the analyst uses ordinal 1–5 consensus ratings rather than empirical frequency data or financial values, so the outputs are relative scores and not defensible monetary estimates for the CRM system.

  • ✗

    Monte Carlo simulation

    Why it's wrong here

    Monte Carlo simulation runs repeated random sampling across probability distributions to model ranges of outcomes and their likelihoods. It is a quantitative technique requiring defined distributions and computational modeling. The analyst here only performed simple multiplication of consensus ratings, so no simulation or probabilistic distribution modeling was involved.

  • ✗

    Qualitative risk analysis

    Why it's wrong here

    Qualitative analysis expresses likelihood and impact in descriptive terms such as high, medium, or low, without converting them to numeric values. Because the analyst assigns numeric ratings and multiplies them into a composite score, the method has moved beyond purely qualitative description even though the underlying judgments remain subjective.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.