Courseiva
IT Risk Identification →mediumMultiple Select

CRISC IT Risk Identification Practice Question

A risk manager is developing risk scenarios to present to the board. Which TWO elements are essential for connecting a risk scenario to business impact?

⚠ Common exam trap

CRISC often tests the confusion between technical severity metrics (vulnerability score, detection time) and business-facing elements (consequence, business impact statement) when linking risk scenarios to organizational impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Consequence (e.g., financial loss)

Option D, consequence such as financial loss, is essential because it translates a technical or threat event into measurable business outcomes (e.g., revenue loss, regulatory fines, recovery cost), which is exactly what connects the scenario to business impact. Option E, a business impact statement, is essential because it formally articulates how the scenario affects business objectives, operations, or stakeholders, providing the board with a clear linkage between risk and organizational impact. Together, consequence and the business impact statement bridge the gap between risk scenarios and business-level decision-making. Option A, threat actor motivation, is useful for threat modeling but does not by itself quantify or express business impact. Option B, vulnerability score, is a technical severity metric (e.g., CVSS) that does not directly map to business consequences. Option C, detection time, is an operational metric that influences exposure but is not an essential element for connecting a scenario to business impact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Threat actor motivation

    Why it's wrong here

    Threat actor motivation explains why an event occurs, not what it costs the organisation, so it cannot connect a scenario to business impact. It is tempting because motivation informs likelihood estimates, and it would be the right element when building the threat half of a risk scenario.

  • ✗

    Vulnerability score

    Why it's wrong here

    A vulnerability score rates the likelihood or severity of a weakness, not the business consequence of a realised risk. Scenarios connect to impact through asset value and business process dependency. Vulnerability scoring belongs in a technical assessment feeding likelihood estimates, not in the impact linkage the board needs.

  • ✗

    Detection time

    Why it's wrong here

    Detection time measures how quickly an event is noticed, not the magnitude of loss, so it cannot link a scenario to business impact. It is tempting because detection capability shapes response, and it would be relevant when assessing control effectiveness rather than impact quantification.

  • ✓

    Consequence (e.g., financial loss)

    Why this is correct

    Consequence quantifies what happens to the organisation if the risk eventuates — financial loss, regulatory penalty or service disruption. It is the causal link translating a risk scenario into measurable business impact, giving the board a basis for comparing scenarios against risk appetite.

  • ✓

    Business impact statement

    Why this is correct

    A business impact statement translates a risk scenario into quantified consequences on objectives, satisfying the stem's requirement to connect scenarios to business impact. It expresses disruption in financial, operational or regulatory terms the board can weigh, rather than describing the threat event itself. This makes the scenario decision-useful for governance oversight.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.