Courseiva
IT Risk AssessmenteasyMultiple ChoiceObjective-mapped

CRISC IT Risk Assessment Practice Question

An organization is evaluating the risk of a data breach using the FAIR framework. Which of the following components is part of Loss Event Frequency (LEF)?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Threat Event Frequency

In FAIR, Loss Event Frequency = Threat Event Frequency × Vulnerability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Threat Event Frequency

    Why this is correct

    Threat Event Frequency is a factor in LEF.

  • Annualized Loss Expectancy

    Why it's wrong here

    ALE is derived from LEF and Loss Magnitude, not a component of LEF.

  • Primary Loss

    Why it's wrong here

    Primary Loss is part of Loss Magnitude, not LEF.

  • Secondary Loss

    Why it's wrong here

    Secondary Loss is part of Loss Magnitude.

About these practice questions

This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.