Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A risk scenario is being developed for a phishing attack leading to credential theft. Using ISACA's risk scenario template, which component would describe the 'threat event'?

⚠ Common exam trap

CRISC often tests the risk scenario template by mixing actor, event, vulnerability, and impact in the answer choices; candidates must isolate the 'event' as the action that occurs, not the actor who performs it or the consequence that follows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A user clicks a malicious link in a phishing email

In ISACA's risk scenario template, the 'threat event' component describes the specific action or occurrence that triggers risk — here, a user clicking a malicious link in a phishing email. This is the initiating event that, combined with the threat actor and vulnerable asset, produces the risk. The threat event is distinct from the threat actor (who), the vulnerability (what weakness), and the impact (what happens next).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A user clicks a malicious link in a phishing email

    Why this is correct

    The threat event is the actual occurrence that initiates harm, so a user clicking a malicious link in a phishing email precisely describes the event itself, distinct from the threat source (external attacker) and the vulnerability (susceptible user). This satisfies the scenario component capturing what happens.

  • ✗

    The organization's email security filter fails to block the phishing email

    Why it's wrong here

    A failed email filter is the vulnerability or control weakness that permits the phishing message to reach the user, not the threat event itself. It is tempting because the filter's failure directly enables the attack, but ISACA's template reserves threat event for the actual occurrence, such as an attacker sending a malicious email.

  • ✗

    The attacker is an organized crime group based overseas

    Why it's wrong here

    An organised crime group describes the threat actor or source, not the threat event. It is tempting because the actor causes the event, but ISACA's template distinguishes the party initiating the attack from the event itself, which is the phishing email being sent and received by the user.

  • ✗

    The compromised credentials are used to access a financial system

    Why it's wrong here

    Using compromised credentials to access a financial system is the threat event's consequence or impact, not the threat event. It is tempting because it is the attacker's action, but the template separates the initiating event (phishing email delivered) from the resulting loss event, which belongs in the impact or consequence component.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.