CRISC IT Risk Assessment Practice Question
A risk analyst is prioritizing remediation efforts across four identified risks. The analyst has likelihood and impact ratings but must also account for the speed at which each risk could materialize and the organization's ability to respond. Which concept is the analyst applying to adjust the prioritization?
⚠ Common exam trap
The trap here is assuming that likelihood multiplied by impact fully determines priority, ignoring how quickly the risk can materialize.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk velocity
Risk velocity captures how fast a risk can produce impact, and it changes prioritization because a fast-moving risk leaves little time for detection and response. Two risks with identical likelihood and impact scores can require very different urgency when one unfolds over months and the other over minutes. Folding velocity and response capability into prioritization directs attention to the exposures where delay is most costly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk appetite
Why it's wrong here
Risk appetite is the amount of risk an organization is willing to accept in pursuit of objectives. It sets thresholds for deciding whether to treat or accept a risk, but it does not itself describe how fast a risk could materialize. The analyst's focus on speed and response capability points to a temporal characteristic of the risk, not to the organization's tolerance boundary.
- ✗
Control maturity
Why it's wrong here
Control maturity describes how well developed and consistently applied a control process is, often measured against a capability model. While mature controls can reduce likelihood or impact, maturity is a property of the control environment rather than a characteristic of how quickly a risk event unfolds. The scenario emphasizes timing and responsiveness, which control maturity alone does not capture.
- ✗
Inherent risk
Why it's wrong here
Inherent risk is the level of risk before controls are applied. It is a foundational measure used to gauge exposure and the value of controls, but it does not incorporate how rapidly an event could occur or how much time the organization has to respond. The analyst is adding a temporal dimension to prioritization, which inherent risk does not provide by itself.
- ✓
Risk velocity
Why this is correct
Risk velocity describes how quickly a risk can materialize and cause impact, which directly affects prioritization beyond static likelihood and impact scores. A risk with moderate likelihood and impact but very high velocity may warrant faster action than a slower, larger risk because there is little time to react. Considering velocity alongside response capability is exactly what the analyst is doing here.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.