CRISC IT Risk Assessment Practice Question
An insurance company is assessing the risk of a distributed denial-of-service (DDoS) attack against its customer portal. The risk team estimates that a threat actor group has both the capability and the intent to launch such an attack, and that the portal has an unpatched vulnerability that could be exploited to amplify the attack. Which factor does the unpatched vulnerability PRIMARILY represent in this risk scenario?
⚠ Common exam trap
The trap here is conflating the threat actor's capability and intent with the vulnerability, when the unpatched flaw is the exploitable weakness rather than the threat itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vulnerability
In risk assessment, vulnerability is the internal weakness or gap that a threat can exploit. The threat actor group provides capability and intent, while impact describes the resulting harm. The unpatched portal flaw is the vulnerability that enables the DDoS amplification, so it is the factor the risk team should prioritize for remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Impact
Why it's wrong here
Impact describes the consequence or harm if the DDoS attack succeeds, such as portal downtime, lost transactions, or reputational damage. The unpatched vulnerability is not the consequence; it is the condition that enables exploitation. Treating it as impact would misdirect mitigation toward recovery planning rather than vulnerability remediation.
- ✗
Threat
Why it's wrong here
The threat is the actor group with the capability and intent to launch a DDoS attack, not the unpatched flaw itself. Confusing the vulnerability with the threat would lead the risk team to focus on threat intelligence rather than on remediating the portal weakness that makes the attack more effective.
- ✗
Risk appetite
Why it's wrong here
Risk appetite is the amount and type of risk an organization is willing to accept in pursuit of objectives. It is a governance threshold, not a technical weakness. The unpatched portal flaw is a specific vulnerability that contributes to risk, and it is unrelated to how much risk the insurer has decided to tolerate.
- ✓
Vulnerability
Why this is correct
This is correct because the unpatched weakness in the portal is a flaw or gap that a threat actor could exploit. In risk assessment, vulnerability represents the internal weakness that, combined with a threat and its potential impact, creates risk. It is the condition that enables the threat actor's capability and intent to translate into a successful DDoS amplification against the customer portal.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.