CRISC IT Risk Identification Practice Question
A risk scenario is being developed for a phishing attack leading to credential theft. Using ISACA's risk scenario template, which component would describe the 'threat event'?
⚠ Common exam trap
CRISC often tests the risk scenario template by mixing actor, event, vulnerability, and impact in the answer choices; candidates must isolate the 'event' as the action that occurs, not the actor who performs it or the consequence that follows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A user clicks a malicious link in a phishing email
In ISACA's risk scenario template, the 'threat event' component describes the specific action or occurrence that triggers risk — here, a user clicking a malicious link in a phishing email. This is the initiating event that, combined with the threat actor and vulnerable asset, produces the risk. The threat event is distinct from the threat actor (who), the vulnerability (what weakness), and the impact (what happens next).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A user clicks a malicious link in a phishing email
Why this is correct
The threat event is the actual occurrence that initiates harm, so a user clicking a malicious link in a phishing email precisely describes the event itself, distinct from the threat source (external attacker) and the vulnerability (susceptible user). This satisfies the scenario component capturing what happens.
- ✗
The organization's email security filter fails to block the phishing email
Why it's wrong here
A failed email filter is the vulnerability or control weakness that permits the phishing message to reach the user, not the threat event itself. It is tempting because the filter's failure directly enables the attack, but ISACA's template reserves threat event for the actual occurrence, such as an attacker sending a malicious email.
- ✗
The attacker is an organized crime group based overseas
Why it's wrong here
An organised crime group describes the threat actor or source, not the threat event. It is tempting because the actor causes the event, but ISACA's template distinguishes the party initiating the attack from the event itself, which is the phishing email being sent and received by the user.
- ✗
The compromised credentials are used to access a financial system
Why it's wrong here
Using compromised credentials to access a financial system is the threat event's consequence or impact, not the threat event. It is tempting because it is the attacker's action, but the template separates the initiating event (phishing email delivered) from the resulting loss event, which belongs in the impact or consequence component.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.