Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

An organization is assessing risks related to a new cloud-based CRM system. The risk team is developing a risk scenario. Which of the following is the BEST example of a complete risk scenario following the ISACA template?

⚠ Common exam trap

CRISC often tests whether candidates can distinguish a complete risk scenario (with actor, threat, asset, timing, detection, consequence) from a simple risk statement that only names a threat and an outcome.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An external attacker (actor) performs a SQL injection (threat type) to exfiltrate customer records from the CRM database (event/asset); occurs during off-hours (timing); detected by IDS after 2 hours (detection); leads to regulatory fines and reputational damage (consequence).

ISACA's risk scenario template requires a structured narrative that identifies the threat actor, threat type, event, asset, timing, detection method, and consequence. Option C is the only choice that includes all these elements — actor (external attacker), threat type (SQL injection), event/asset (exfiltration from CRM database), timing (off-hours), detection (IDS after 2 hours), and consequence (regulatory fines and reputational damage). This completeness is what makes it a valid risk scenario rather than a vague risk statement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A DDoS attack on the CRM disrupts service, leading to operational downtime.

    Why it's wrong here

    The ISACA scenario template requires threat, asset, event, and business impact; this entry names a threat and disruption but omits the asset and the specific business consequence. It tempts because DDoS against a CRM is realistic, yet a complete scenario must articulate the affected asset and quantified impact.

  • ✗

    A hacker exploits a vulnerability in the CRM to steal customer data, resulting in financial loss.

    Why it's wrong here

    A hacker exploiting a CRM vulnerability names a threat and impact but omits the asset and, critically, the business risk or consequence linking them, so it fails ISACA's complete scenario template. It tempts because threat-event-impact phrasing suits incident narratives or threat modelling, where identifying an attack vector and its loss is the goal.

  • ✓

    An external attacker (actor) performs a SQL injection (threat type) to exfiltrate customer records from the CRM database (event/asset); occurs during off-hours (timing); detected by IDS after 2 hours (detection); leads to regulatory fines and reputational damage (consequence).

    Why this is correct

    A complete ISACA risk scenario names the actor, threat type, event and affected asset, timing, detection, and consequence. This option supplies all six elements, describing an external attacker using SQL injection to exfiltrate customer records, with detection delay and resulting regulatory and reputational impact.

  • ✗

    A disgruntled employee leaks data from the CRM, causing reputational damage.

    Why it's wrong here

    This entry identifies a threat and impact but omits the asset and the event linking them, so it fails the ISACA scenario structure. It tempts because insider data leakage is a credible CRM risk, but the template demands threat, asset, event, and impact stated explicitly.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.