CRISC IT Risk Assessment Practice Question
A risk practitioner is assessing a new e-commerce platform. The business owner insists that the platform must be available 24/7. The practitioner identifies that a distributed denial-of-service (DDoS) attack could cause an outage. Which of the following BEST describes the risk scenario?
⚠ Common exam trap
The trap here is reversing threat and vulnerability roles or focusing only on the control failure without identifying the threat event and impact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A threat event (DDoS attack) exploiting a vulnerability (inadequate DDoS protection) leading to an impact (loss of availability)
A well-formed risk scenario describes a threat event exploiting a vulnerability to produce an impact on business objectives. The DDoS attack is the threat, inadequate DDoS protection is the vulnerability, and loss of availability is the impact. This structure supports consistent risk assessment and treatment planning, and it directly connects to the business owner's availability requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A risk that is inherent to the e-commerce platform and cannot be mitigated, so it must be accepted
Why it's wrong here
This option prematurely concludes that the risk cannot be mitigated and must be accepted. DDoS risks can be mitigated with controls such as traffic filtering, content delivery networks, and redundancy. The scenario asks for the best description of the risk scenario, not the treatment decision. Accepting without analysis is not appropriate here.
- ✗
A control failure (lack of DDoS protection) that directly causes a financial loss without any threat event
Why it's wrong here
This omits the threat event entirely. A control failure alone does not constitute a risk scenario; there must be a threat that exploits the vulnerability. The DDoS attack is the threat event that triggers the loss. Describing only the control failure would understate the risk and mislead the risk assessment.
- ✗
A vulnerability (DDoS attack) causing a threat event (inadequate DDoS protection) resulting in a loss of confidentiality
Why it's wrong here
This reverses the roles: a DDoS attack is a threat event, not a vulnerability, and inadequate DDoS protection is a vulnerability, not a threat event. Also, a DDoS attack primarily affects availability, not confidentiality. This misclassification would lead to incorrect risk analysis and inappropriate treatment decisions.
- ✓
A threat event (DDoS attack) exploiting a vulnerability (inadequate DDoS protection) leading to an impact (loss of availability)
Why this is correct
This option correctly structures the risk as a threat event exploiting a vulnerability to cause an impact on a business objective. In CRISC, risk scenarios should link threat, vulnerability, and impact. The DDoS attack is the threat event, the inadequate protection is the vulnerability, and the loss of availability of the e-commerce platform is the impact, which aligns with the business owner's availability requirement.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.