Courseiva
IT Risk Assessment →mediumMultiple Choice

CRISC IT Risk Assessment Practice Question

An insurance company is assessing the risk of a distributed denial-of-service (DDoS) attack against its customer portal. The risk team estimates that a threat actor group has both the capability and the intent to launch such an attack, and that the portal has an unpatched vulnerability that could be exploited to amplify the attack. Which factor does the unpatched vulnerability PRIMARILY represent in this risk scenario?

⚠ Common exam trap

The trap here is conflating the threat actor's capability and intent with the vulnerability, when the unpatched flaw is the exploitable weakness rather than the threat itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vulnerability

In risk assessment, vulnerability is the internal weakness or gap that a threat can exploit. The threat actor group provides capability and intent, while impact describes the resulting harm. The unpatched portal flaw is the vulnerability that enables the DDoS amplification, so it is the factor the risk team should prioritize for remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Impact

    Why it's wrong here

    Impact describes the consequence or harm if the DDoS attack succeeds, such as portal downtime, lost transactions, or reputational damage. The unpatched vulnerability is not the consequence; it is the condition that enables exploitation. Treating it as impact would misdirect mitigation toward recovery planning rather than vulnerability remediation.

  • ✗

    Threat

    Why it's wrong here

    The threat is the actor group with the capability and intent to launch a DDoS attack, not the unpatched flaw itself. Confusing the vulnerability with the threat would lead the risk team to focus on threat intelligence rather than on remediating the portal weakness that makes the attack more effective.

  • ✗

    Risk appetite

    Why it's wrong here

    Risk appetite is the amount and type of risk an organization is willing to accept in pursuit of objectives. It is a governance threshold, not a technical weakness. The unpatched portal flaw is a specific vulnerability that contributes to risk, and it is unrelated to how much risk the insurer has decided to tolerate.

  • ✓

    Vulnerability

    Why this is correct

    This is correct because the unpatched weakness in the portal is a flaw or gap that a threat actor could exploit. In risk assessment, vulnerability represents the internal weakness that, combined with a threat and its potential impact, creates risk. It is the condition that enables the threat actor's capability and intent to translate into a successful DDoS amplification against the customer portal.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.