Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A risk practitioner at a healthcare payer is building the risk identification taxonomy for a new claims-processing platform. The CISO asks why the taxonomy must explicitly distinguish between a 'threat event' and a 'loss event' rather than treating both as 'risk' in the register. Which statement BEST justifies that distinction?

⚠ Common exam trap

The trap here is assuming the difference between a threat event and a loss event is who caused it rather than whether adverse impact has actually been realized.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A threat event is a potential occurrence that may exploit a vulnerability, while a loss event is a realized occurrence that has already produced an adverse business impact.

The taxonomy must separate potential from realized occurrences because likelihood estimation attaches to threat events while impact estimation attaches to events that have actually caused harm. A threat event may exploit a vulnerability without ever producing loss, and a loss event confirms that the exposure materialized. Keeping them distinct allows the practitioner to model scenarios, set likelihood and impact parameters independently, and later feed realized outcomes back into the assessment to validate or adjust prior estimates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A threat event is measured only in monetary terms, while a loss event is measured only in qualitative severity ratings such as high, medium, or low.

    Why it's wrong here

    This reverses and misapplies measurement practice. Threat likelihood is typically expressed as frequency or probability, and impact may be either quantitative or qualitative. Loss events are the ones that frequently carry quantified financial figures because they have already occurred and can be measured. Forcing threat events into monetary terms and loss events into ordinal ratings would make the healthcare payer's scenario analysis internally inconsistent and unusable for comparing risk against tolerance.

  • ✗

    A threat event is recorded only in the risk register, while a loss event is recorded only in the incident management system, so the two never need to be linked.

    Why it's wrong here

    Records may live in different systems, but CRISC requires traceability between them. A realized loss event should be traceable back to the threat scenarios and risk register entries it validates or invalidates, otherwise likelihood estimates are never recalibrated from actual experience. Asserting that the two never need linkage removes the feedback loop that keeps the risk assessment current and prevents the practitioner from demonstrating whether existing controls actually reduced loss frequency or magnitude.

  • ✗

    A threat event is always externally sourced from attackers, whereas a loss event is always internally sourced from employee error or process failure.

    Why it's wrong here

    This confuses source with timing. Threat events can originate internally, such as a privileged administrator error or an insider with authorized access, and loss events can be caused by external attackers, as with ransomware that encrypts production data. The distinguishing characteristic is potential versus realized impact, not the internal or external origin of the actor. Using source as the classifier would misroute numerous risks in the healthcare claims environment and distort ownership assignments.

  • ✓

    A threat event is a potential occurrence that may exploit a vulnerability, while a loss event is a realized occurrence that has already produced an adverse business impact.

    Why this is correct

    This is the correct framing. In CRISC terminology, a threat event is a circumstance or occurrence with the potential to cause loss by exploiting a vulnerability; it has not yet produced impact. A loss event is the materialized outcome that has actually generated adverse business, financial, or regulatory consequences. Separating them lets the practitioner model likelihood against threats and model impact only against realized events, which keeps scenario estimation and control design logically consistent across the taxonomy.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.