CRISC IT Risk Identification Practice Question
A risk practitioner is developing a risk scenario for a potential ransomware attack. Using the ISACA risk scenario template, which element describes the entity that initiates the attack?
⚠ Common exam trap
Watch out — candidates often confuse 'Actor' with 'Threat type' because both relate to the threat, but the Actor is the who (initiator) while Threat type is the what (category of threat).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Actor
In the ISACA risk scenario template, the 'Actor' element specifically identifies the entity that initiates or perpetrates the attack. For a ransomware attack, the actor could be an external hacker, a malicious insider, or a cybercriminal group, making option C the correct choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Event
Why it's wrong here
An event is the occurrence or incident itself — the ransomware detonation — not the actor behind it. It is tempting because scenarios often pivot on the event, and naming the threat event feels central, but the template's actor element (threat actor/initiator) is what identifies who launches the attack.
- ✗
Threat type
Why it's wrong here
Threat type classifies the nature of the threat, not the actor initiating it; the template's threat actor or actor element names the initiating entity. Threat type is tempting because it also describes the attack, and it would be correct when categorising the method rather than identifying who acts.
- ✓
Actor
Why this is correct
The ISACA risk scenario template separates threat actor, threat event, asset, and consequence. The actor element names the party initiating the attack, such as an external ransomware group, distinguishing it from the event or impact fields.
- ✗
Asset/Resource
Why it's wrong here
Asset/Resource identifies what is targeted or affected, not who initiates the attack. It is tempting because ransomware scenarios must name the impacted asset, and asset value drives risk, but the initiating entity is the threat actor element, not the resource being attacked.
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.