Courseiva
IT Risk Identification →hardMultiple Choice

CRISC IT Risk Identification Practice Question

A risk practitioner is developing a risk scenario for a potential ransomware attack. Using the ISACA risk scenario template, which element describes the entity that initiates the attack?

⚠ Common exam trap

Watch out — candidates often confuse 'Actor' with 'Threat type' because both relate to the threat, but the Actor is the who (initiator) while Threat type is the what (category of threat).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Actor

In the ISACA risk scenario template, the 'Actor' element specifically identifies the entity that initiates or perpetrates the attack. For a ransomware attack, the actor could be an external hacker, a malicious insider, or a cybercriminal group, making option C the correct choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Event

    Why it's wrong here

    An event is the occurrence or incident itself — the ransomware detonation — not the actor behind it. It is tempting because scenarios often pivot on the event, and naming the threat event feels central, but the template's actor element (threat actor/initiator) is what identifies who launches the attack.

  • ✗

    Threat type

    Why it's wrong here

    Threat type classifies the nature of the threat, not the actor initiating it; the template's threat actor or actor element names the initiating entity. Threat type is tempting because it also describes the attack, and it would be correct when categorising the method rather than identifying who acts.

  • ✓

    Actor

    Why this is correct

    The ISACA risk scenario template separates threat actor, threat event, asset, and consequence. The actor element names the party initiating the attack, such as an external ransomware group, distinguishing it from the event or impact fields.

  • ✗

    Asset/Resource

    Why it's wrong here

    Asset/Resource identifies what is targeted or affected, not who initiates the attack. It is tempting because ransomware scenarios must name the impacted asset, and asset value drives risk, but the initiating entity is the threat actor element, not the resource being attacked.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.