Courseiva
IT Risk Assessment →easyMultiple Choice

CRISC IT Risk Assessment Practice Question

An organization is evaluating the risk of a data breach using the FAIR framework. Which of the following components is part of Loss Event Frequency (LEF)?

⚠ Common exam trap

CRISC often tests FAIR taxonomy, so the trap is confusing LEF components (Threat Event Frequency, Vulnerability) with Loss Magnitude components (Primary Loss, Secondary Loss) or with derived metrics like ALE.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Threat Event Frequency

In the FAIR (Factor Analysis of Information Risk) ontology, Loss Event Frequency (LEF) is composed of Threat Event Frequency (TEF) and Vulnerability (the probability that a threat event becomes a loss event). Threat Event Frequency is therefore a direct component of LEF. Annualized Loss Expectancy, Primary Loss, and Secondary Loss belong to the loss magnitude side of the model, not LEF.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Threat Event Frequency

    Why this is correct

    Loss Event Frequency decomposes into Threat Event Frequency and Vulnerability, so Threat Event Frequency is a direct LEF input. It measures how often threat agents act against the asset, which then combines with vulnerability to yield loss event frequency.

  • ✗

    Annualized Loss Expectancy

    Why it's wrong here

    Annualized Loss Expectancy quantifies monetary loss per year, sitting in FAIR's risk-output layer rather than Loss Event Frequency, which combines threat event frequency with vulnerability. It tempts because ALE is a recognised risk-quantification metric, and would be the correct choice when asked to express total expected annual financial exposure.

  • ✗

    Primary Loss

    Why it's wrong here

    Primary Loss forms part of Loss Magnitude in FAIR, measuring the direct costs borne by the affected organisation, not the frequency of threat events. It is tempting because it is a named FAIR component; it would be correct when quantifying the immediate financial impact of a single loss event.

  • ✗

    Secondary Loss

    Why it's wrong here

    Secondary Loss sits in the FAIR taxonomy under Loss Magnitude, not Loss Event Frequency, so it cannot answer a question scoped to LEF. It is tempting because secondary losses — regulatory fines, customer churn, remediation costs — dominate breach impact estimates, making it the correct choice when quantifying how much a given event would cost rather than how often it occurs.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.