Courseiva
IT Risk Assessment →hardMultiple Select

CRISC IT Risk Assessment Practice Question

An organization is performing a quantitative risk analysis using the FAIR framework. Which THREE of the following are direct components of the FAIR model?

⚠ Common exam trap

CRISC often tests the difference between FAIR's factor decomposition (Threat Event Frequency, Vulnerability, Loss Event Frequency) and traditional ALE/SLE formulas — candidates mix the two frameworks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Loss Event Frequency

In the FAIR (Factor Analysis of Information Risk) ontology, Loss Event Frequency (B) is a core top-level factor representing how often loss events occur, and it is decomposed into Threat Event Frequency and Vulnerability. Threat Event Frequency (C) is a direct component of FAIR, describing the probable frequency with which threat agents act against an asset. Vulnerability (E) is also a direct FAIR component, defined as the probability that a threat event becomes a loss event, and it combines with Threat Event Frequency to derive Loss Event Frequency. By contrast, Single Loss Expectancy (A) and Annualized Loss Expectancy (D) are classic qualitative/quantitative risk formulas from traditional risk analysis (SLE = asset value × exposure factor; ALE = SLE × ARO), not native FAIR ontology components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Single Loss Expectancy

    Why it's wrong here

    SLE belongs to traditional ALE arithmetic, whereas FAIR decomposes loss into primary loss and secondary loss, each with six forms. It is tempting because SLE is the standard single-event loss figure taught alongside ARO, so it looks like a natural FAIR input when calculating annualised exposure.

  • ✓

    Loss Event Frequency

    Why this is correct

    Loss Event Frequency is a core FAIR factor, combining Threat Event Frequency and Vulnerability to express how often loss events occur. It satisfies the stem's requirement for a direct model component, sitting on the frequency axis of risk, which FAIR quantifies as Loss Event Frequency multiplied by Loss Magnitude.

  • ✓

    Threat Event Frequency

    Why this is correct

    Threat Event Frequency is a core FAIR factor, quantifying how often threat agents are expected to act against an asset within a given period. It feeds directly into Loss Event Frequency alongside Vulnerability, satisfying the stem's requirement for a direct model component rather than a derived or external metric.

  • ✗

    Annualized Loss Expectancy

    Why it's wrong here

    ALE is a classic risk-management output, not a FAIR factor; FAIR derives loss magnitude from primary and secondary loss, then annualises frequency separately. It is tempting because ALE appears in older quantitative methods such as NIST SP 800-30 and combines SLE with annualised rate of occurrence, so analysts reuse it as a familiar aggregate.

  • ✓

    Vulnerability

    Why this is correct

    Vulnerability is a direct FAIR component, representing the probability that a threat event becomes a loss event given existing controls. It sits within the Loss Event Frequency branch alongside threat event frequency, and is distinct from secondary, organisational or framework-level factors.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.