CRISC IT Risk Assessment Practice Question
A risk practitioner is facilitating a risk assessment workshop for a new cloud-based HR system. The team is identifying threats. Which TWO of the following are examples of threat events that should be considered? (Choose two.)
⚠ Common exam trap
The trap here is listing vulnerabilities as threats, which confuses the two and leads to incomplete risk scenarios.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A natural disaster causing a cloud data center outage
Threat events are occurrences or actions that can cause harm, such as a malicious insider exfiltrating data or a natural disaster causing an outage. Vulnerabilities like unpatched software, lack of encryption, or inadequate training are conditions that threats may exploit. Distinguishing between threats and vulnerabilities is essential for accurate risk scenarios.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An unpatched web server software vulnerability
Why it's wrong here
An unpatched software vulnerability is a weakness, not a threat event. It can be exploited by a threat, but by itself it is not an event. In risk assessment, vulnerabilities are identified separately from threats. Confusing the two can lead to incomplete risk scenarios because the threat actor or event is missing.
- ✓
A natural disaster causing a cloud data center outage
Why this is correct
A natural disaster causing a data center outage is a threat event. It can lead to loss of availability of the HR system. Even though the cloud provider may have controls, the organization should consider this threat as part of its risk assessment, especially for critical systems. It is an external event with potential business impact.
- ✓
A malicious insider exfiltrating employee personal data
Why this is correct
A malicious insider exfiltrating data is a threat event because it is an action with the potential to cause harm. It exploits vulnerabilities such as excessive access privileges or lack of monitoring. In the context of a cloud HR system, this threat is relevant due to the sensitive nature of employee data and the need to consider insider risk.
- ✗
Lack of encryption for data at rest
Why it's wrong here
Lack of encryption is a vulnerability or control gap, not a threat event. It increases the likelihood or impact of a threat such as data theft, but it does not cause harm on its own. Threat identification should focus on what can happen, while vulnerabilities are conditions that enable threats.
- ✗
Inadequate security awareness training for employees
Why it's wrong here
Inadequate training is a vulnerability, not a threat event. It can make other threats more likely, such as phishing success, but it is not an event itself. Including it as a threat would misrepresent the risk scenario and could lead to incorrect treatment prioritization.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.