CRISC IT Risk Identification Practice Question
A risk practitioner is using the MITRE ATT&CK framework to identify threats relevant to a financial services firm's cloud-hosted trading platform. The practitioner wants to focus on techniques adversaries use after obtaining initial access to cloud infrastructure. Which of the following BEST describes how ATT&CK should be applied in this risk identification effort?
⚠ Common exam trap
The trap here is treating ATT&CK as a scoring or taxonomy replacement framework, when its actual role is to describe adversary behavior that must be mapped to assets and controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Map relevant ATT&CK techniques to the platform's assets and controls to identify gaps in detection and mitigation coverage.
ATT&CK is most valuable in risk identification when its techniques are mapped to the organization's assets and existing controls, exposing coverage gaps in detection and mitigation. It describes adversary behavior but does not supply likelihood scores, replace a risk taxonomy, or determine budget priorities by itself. The practitioner should use the mapping to build credible scenarios and then combine that insight with likelihood, impact, and risk appetite to drive treatment decisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Replace the organization's risk taxonomy with ATT&CK tactic categories to simplify risk register reporting.
Why it's wrong here
ATT&CK tactics describe adversary goals and are not a substitute for an enterprise risk taxonomy, which organizes risks by business impact and asset. Replacing the taxonomy would break alignment with governance, compliance, and board reporting. ATT&CK enriches risk identification with adversary behavior detail; it does not replace the structure used to categorize and report risk. The scenario asks how to apply ATT&CK, not how to restructure the risk register.
- ✗
Use ATT&CK technique identifiers as the sole basis for prioritizing risk treatment budgets across the firm.
Why it's wrong here
ATT&CK technique identifiers indicate adversary behavior, not business criticality or financial exposure. Prioritizing budgets solely by technique would ignore asset value, regulatory obligations, and impact magnitude. The framework supports identification and coverage assessment; prioritization requires combining its output with likelihood, impact, and risk appetite. Using it as the sole basis would misallocate resources toward interesting techniques rather than the risks that matter most to the firm.
- ✓
Map relevant ATT&CK techniques to the platform's assets and controls to identify gaps in detection and mitigation coverage.
Why this is correct
ATT&CK is designed to describe adversary behavior in a structured way, and mapping its techniques to assets and controls reveals where detection and mitigation coverage is missing. For a cloud trading platform, this could highlight weak coverage of credential access or data exfiltration techniques. The output feeds risk identification by showing which credible adversary behaviors are not addressed, enabling the practitioner to build scenarios grounded in real tactics rather than generic threat lists.
- ✗
Use ATT&CK techniques to assign a numerical likelihood score to each identified risk in the register.
Why it's wrong here
ATT&CK is a knowledge base of adversary tactics and techniques, not a likelihood scoring model. It does not provide probability values or frequency data. Using it to assign numerical likelihood scores would produce arbitrary results unsupported by the framework. The framework helps identify what adversaries may do, which then informs scenario development; likelihood must be estimated separately using threat intelligence, historical incident data, and expert judgment.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.