Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A risk practitioner at a healthcare insurance company is building the risk register entry for ransomware affecting its claims-processing platform. The practitioner must document the loss event type, the asset at risk, and the expected loss magnitude in the organization's risk taxonomy. Which of the following BEST describes the risk component that represents the expected loss magnitude?

⚠ Common exam trap

Test-takers frequently confuse likelihood or inherent risk level with expected loss magnitude, when only the financially expressed business impact represents the magnitude component of the risk scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The business impact, expressed in financial terms, if the ransomware event actually occurs and disrupts claims processing.

Expected loss magnitude is captured as business impact expressed in financial terms, answering how much the organization would lose if the ransomware event disrupted claims processing. Likelihood, inherent risk, and control effectiveness are distinct components that feed into risk analysis but do not themselves quantify the consequence. Documenting financial impact enables meaningful comparison against risk appetite and supports prioritization of treatment options.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The likelihood that a ransomware actor will attempt to compromise the claims-processing platform within the next twelve months.

    Why it's wrong here

    Likelihood estimates the probability or frequency of the threat event occurring; it is a separate component from loss magnitude. The scenario specifically asks about expected loss magnitude, not how probable the event is. A high likelihood with low impact differs materially from low likelihood with high impact, so likelihood alone cannot represent the financial consequence being documented in the register.

  • ✗

    The inherent risk level assigned to the claims-processing platform before any controls are applied.

    Why it's wrong here

    Inherent risk expresses exposure before controls are considered, but it does not quantify expected loss magnitude. The scenario asks for the expected loss magnitude component, which is a monetary or impact estimate tied to the realized loss event. Inherent risk is a relative rating, not the quantified expected loss, so it does not satisfy the requirement of documenting loss magnitude in the taxonomy.

  • ✓

    The business impact, expressed in financial terms, if the ransomware event actually occurs and disrupts claims processing.

    Why this is correct

    Business impact in financial terms is the expected loss magnitude component of a risk scenario. It captures the monetary consequence if the ransomware event materializes against the claims-processing platform. This aligns with ISACA risk scenario anatomy, where impact answers how much loss would result. Documenting this value supports risk ranking, treatment decisions, and comparison against the organization's risk appetite.

  • ✗

    The control effectiveness rating of the endpoint detection and backup controls protecting the claims-processing platform.

    Why it's wrong here

    Control effectiveness describes how well mitigating controls reduce likelihood or impact; it is an input to residual risk, not the loss magnitude itself. While stronger controls may lower expected loss, the control rating is not the expected loss quantity. The scenario requires documenting the loss magnitude component, which is expressed as business impact, not as an assessment of control performance.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.