CRISC IT Risk Assessment Practice Question
An organization is evaluating the risk of a data breach using the FAIR framework. Which of the following components is part of Loss Event Frequency (LEF)?
⚠ Common exam trap
CRISC often tests FAIR taxonomy, so the trap is confusing LEF components (Threat Event Frequency, Vulnerability) with Loss Magnitude components (Primary Loss, Secondary Loss) or with derived metrics like ALE.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat Event Frequency
In the FAIR (Factor Analysis of Information Risk) ontology, Loss Event Frequency (LEF) is composed of Threat Event Frequency (TEF) and Vulnerability (the probability that a threat event becomes a loss event). Threat Event Frequency is therefore a direct component of LEF. Annualized Loss Expectancy, Primary Loss, and Secondary Loss belong to the loss magnitude side of the model, not LEF.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Threat Event Frequency
Why this is correct
Loss Event Frequency decomposes into Threat Event Frequency and Vulnerability, so Threat Event Frequency is a direct LEF input. It measures how often threat agents act against the asset, which then combines with vulnerability to yield loss event frequency.
- ✗
Annualized Loss Expectancy
Why it's wrong here
Annualized Loss Expectancy quantifies monetary loss per year, sitting in FAIR's risk-output layer rather than Loss Event Frequency, which combines threat event frequency with vulnerability. It tempts because ALE is a recognised risk-quantification metric, and would be the correct choice when asked to express total expected annual financial exposure.
- ✗
Primary Loss
Why it's wrong here
Primary Loss forms part of Loss Magnitude in FAIR, measuring the direct costs borne by the affected organisation, not the frequency of threat events. It is tempting because it is a named FAIR component; it would be correct when quantifying the immediate financial impact of a single loss event.
- ✗
Secondary Loss
Why it's wrong here
Secondary Loss sits in the FAIR taxonomy under Loss Magnitude, not Loss Event Frequency, so it cannot answer a question scoped to LEF. It is tempting because secondary losses — regulatory fines, customer churn, remediation costs — dominate breach impact estimates, making it the correct choice when quantifying how much a given event would cost rather than how often it occurs.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.