CRISC IT Risk Assessment Practice Question
An organization is performing a quantitative risk analysis using the FAIR framework. Which THREE of the following are direct components of the FAIR model?
⚠ Common exam trap
CRISC often tests the difference between FAIR's factor decomposition (Threat Event Frequency, Vulnerability, Loss Event Frequency) and traditional ALE/SLE formulas — candidates mix the two frameworks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Loss Event Frequency
In the FAIR (Factor Analysis of Information Risk) ontology, Loss Event Frequency (B) is a core top-level factor representing how often loss events occur, and it is decomposed into Threat Event Frequency and Vulnerability. Threat Event Frequency (C) is a direct component of FAIR, describing the probable frequency with which threat agents act against an asset. Vulnerability (E) is also a direct FAIR component, defined as the probability that a threat event becomes a loss event, and it combines with Threat Event Frequency to derive Loss Event Frequency. By contrast, Single Loss Expectancy (A) and Annualized Loss Expectancy (D) are classic qualitative/quantitative risk formulas from traditional risk analysis (SLE = asset value × exposure factor; ALE = SLE × ARO), not native FAIR ontology components.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Single Loss Expectancy
Why it's wrong here
SLE belongs to traditional ALE arithmetic, whereas FAIR decomposes loss into primary loss and secondary loss, each with six forms. It is tempting because SLE is the standard single-event loss figure taught alongside ARO, so it looks like a natural FAIR input when calculating annualised exposure.
- ✓
Loss Event Frequency
Why this is correct
Loss Event Frequency is a core FAIR factor, combining Threat Event Frequency and Vulnerability to express how often loss events occur. It satisfies the stem's requirement for a direct model component, sitting on the frequency axis of risk, which FAIR quantifies as Loss Event Frequency multiplied by Loss Magnitude.
- ✓
Threat Event Frequency
Why this is correct
Threat Event Frequency is a core FAIR factor, quantifying how often threat agents are expected to act against an asset within a given period. It feeds directly into Loss Event Frequency alongside Vulnerability, satisfying the stem's requirement for a direct model component rather than a derived or external metric.
- ✗
Annualized Loss Expectancy
Why it's wrong here
ALE is a classic risk-management output, not a FAIR factor; FAIR derives loss magnitude from primary and secondary loss, then annualises frequency separately. It is tempting because ALE appears in older quantitative methods such as NIST SP 800-30 and combines SLE with annualised rate of occurrence, so analysts reuse it as a familiar aggregate.
- ✓
Vulnerability
Why this is correct
Vulnerability is a direct FAIR component, representing the probability that a threat event becomes a loss event given existing controls. It sits within the Loss Event Frequency branch alongside threat event frequency, and is distinct from secondary, organisational or framework-level factors.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.