Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A risk practitioner at a regional bank is building risk scenarios for the new mobile check deposit feature. The team has identified the event 'attackers exploit a vulnerability in the image processing library to inject malicious code.' Which of the following BEST describes the element that is missing from this risk scenario?

⚠ Common exam trap

The trap here is assuming a detailed threat description is enough to form a complete risk scenario, when the asset and business impact are equally required components.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The asset or business process affected and the resulting business impact.

ISACA describes a risk scenario as a threat event acting on an asset or process and producing a business impact. The stem supplies the threat and vulnerability but omits the affected asset and consequence, so the practitioner cannot assess likelihood or impact meaningfully. Adding the asset and impact makes the scenario actionable for risk analysis and prioritization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The threat community profile, including capability and intent.

    Why it's wrong here

    The scenario already names the actors as attackers and the method as exploitation of the image processing library, so the threat side is represented. Adding a full threat community profile would enrich context but would not supply the missing component, which is the business consequence the risk practitioner must articulate for the scenario to be usable in risk analysis.

  • ✗

    The control environment currently in place to mitigate the event.

    Why it's wrong here

    Existing controls are relevant to analyzing likelihood and impact, but ISACA scenario construction begins with event, asset/process, and impact. Controls are layered on afterward during risk assessment. Their absence does not make the scenario incomplete in the same fundamental way as the missing asset and business impact, which are the core components being sought.

  • ✓

    The asset or business process affected and the resulting business impact.

    Why this is correct

    A complete risk scenario pairs a threat event with the asset or process it affects and the resulting business impact. The statement describes only the threat and vulnerability; without naming the affected asset, such as the customer deposit process or the image processing service, and the impact, such as fraudulent deposits or regulatory exposure, the scenario cannot be evaluated or prioritized.

  • ✗

    The regulatory requirement that mandates protection of customer data.

    Why it's wrong here

    Regulatory drivers may inform impact estimates, but they are not a required structural element of a risk scenario. The practitioner first needs the asset or process and the business consequence; regulation is one possible source of consequence, not the missing building block. Naming a specific regulation would narrow the scenario prematurely and does not complete the threat-event-plus-impact structure.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.