CRISC IT Risk Identification Practice Question
A risk practitioner is assessing the likelihood that a nation-state actor will exfiltrate intellectual property from an aerospace manufacturer. The practitioner wants to express likelihood using a factor that reflects how attractive the manufacturer is as a target relative to its peers. Which approach BEST supports this?
⚠ Common exam trap
The trap here is substituting easily counted control metrics, such as malware hits or scan findings, for a judgment about adversary targeting intent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Score likelihood using a threat attractiveness rating that weighs sector, data value, and geopolitical relevance.
Likelihood for a deliberate, actor-driven threat should reflect the adversary's intent and the target's relative appeal, not the volume of incidental events or control gaps. A threat attractiveness rating built from sector, data value, and geopolitical relevance captures why a nation-state would choose this aerospace manufacturer, keeps the likelihood factor independent of impact and vulnerability inputs, and gives a stable basis for comparing the same risk over successive assessment cycles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assess likelihood by the number of open vulnerabilities rated critical in the last external scan.
Why it's wrong here
Critical vulnerability counts measure exposure and control weakness, which belong on the impact or vulnerability side of the risk equation, not on adversary intent. A manufacturer could have a flawless patch posture and still be targeted because of what it designs. Treating scan findings as likelihood collapses two distinct risk factors and produces a score that changes with every scan cycle, making it unstable for tracking the same espionage risk over time.
- ✗
Derive likelihood from the annualized loss expectancy calculated for previous intellectual property incidents.
Why it's wrong here
Annualized loss expectancy is an output of quantitative risk analysis that combines frequency and monetary impact, so using it as the likelihood input is circular and double-counts impact. Historical IP incidents are also rare and often undetected, making the sample statistically weak. This method would produce a misleadingly low likelihood for a well-defended firm that simply has not yet observed a successful nation-state exfiltration.
- ✓
Score likelihood using a threat attractiveness rating that weighs sector, data value, and geopolitical relevance.
Why this is correct
A threat attractiveness rating expresses how desirable the organization is as a target by combining factors such as industry sector, the value of the intellectual property it holds, and its geopolitical profile. This directly captures the adversary's motivation to select this manufacturer over other targets, which is the appropriate likelihood input for a deliberate, actor-driven threat, and it remains stable enough to track as the risk landscape evolves.
- ✗
Rate likelihood using the historical frequency of malware infections recorded by the endpoint protection platform.
Why it's wrong here
Endpoint malware infection counts reflect commodity threats that reach the estate, not the deliberate targeting decisions of a nation-state actor. An aerospace manufacturer may see very few commodity infections while remaining a high-value espionage target. Using this frequency would systematically understate likelihood for the threat in question and would mislead the risk treatment plan toward endpoint controls instead of the counterintelligence and supply chain protections the scenario requires.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.