CRISC IT Risk Identification Practice Question
A risk practitioner at a regional bank is building a risk register entry for the loss of a critical core banking application. The head of IT operations insists on recording a single, point-in-time likelihood estimate of 15% derived from last year's incident log, and refuses to consider any range. Which CRISC-aligned principle should the practitioner apply to MOST appropriately represent this IT risk?
⚠ Common exam trap
The trap here is assuming that a precise-looking percentage from historical logs is inherently more defensible than a range, when in fact it conceals the uncertainty that risk analysis exists to surface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Model likelihood and impact as distributions reflecting uncertainty around the estimates.
Expressing likelihood and impact as distributions acknowledges that estimates carry uncertainty, which is central to sound IT risk analysis. A point estimate of 15% implies false precision and hides tail risk that could threaten the core banking service. Distributions let the bank compare risk against tolerance, prioritize controls, and communicate exposure honestly to stakeholders without overstating confidence in a single number.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Replace the likelihood figure with the industry average downtime for comparable core banking platforms.
Why it's wrong here
Substituting a peer benchmark discards the bank's own loss data and control environment. Industry averages may not reflect this institution's architecture, patch cadence, or geographic threat profile, so the resulting register entry would misstate its actual exposure. Benchmarks are useful as a sanity check or calibration input, but they are not a substitute for entity-specific likelihood analysis in a risk register.
- ✗
Escalate the disagreement to the board and let it decide whether the 15% figure is acceptable.
Why it's wrong here
The board sets risk appetite and tolerance, not the technical form of an estimate. Escalating a methodological question to the board wastes governance time and still leaves the register with an unsound single-point value. The practitioner's role is to apply sound analysis methods and present ranges so leadership can judge acceptability against appetite.
- ✗
Multiply the 15% likelihood by the maximum credible loss to obtain a single annualized loss expectancy.
Why it's wrong here
Single-factor annualized loss expectancy collapses both dimensions into one number and hides the variability that matters for capital and control decisions. Using the maximum credible loss also biases the result toward an extreme outlier rather than an expected value. It produces a deceptively precise figure without the uncertainty context that informed risk decisions require.
- ✓
Model likelihood and impact as distributions reflecting uncertainty around the estimates.
Why this is correct
Risk is inherently uncertain, so a single point estimate overstates precision. Representing likelihood and impact as distributions captures the range of plausible outcomes and lets the bank compare exposures and set tolerances realistically. This aligns with IT risk analysis principles where frequency and magnitude are estimated with ranges, and it gives decision makers visibility into tail scenarios rather than a false sense of accuracy.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.