Courseiva

CRISC Information Technology and Security Practice Question

An organization uses the FAIR (Factor Analysis of Information Risk) model to quantify cyber risk. Which of the following is the correct definition of 'Loss Magnitude' in the FAIR model?

⚠ Common exam trap

The trap is conflating Loss Magnitude with Loss Event Frequency — candidates often pick the probability-based answer because both are core FAIR terms, but only LM describes financial impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The probable financial impact of a cyber incident

In FAIR, Loss Magnitude represents the probable financial impact resulting from a loss event — it quantifies how much money an organization would lose if a threat event materializes into a loss. It is one of the two primary factors (alongside Loss Event Frequency) that combine to produce risk. It encompasses primary and secondary loss forms across productivity, response, replacement, fines, and reputation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The probable financial impact of a cyber incident

    Why this is correct

    Loss Magnitude in FAIR represents the total monetary loss an organisation would incur from a single loss event, combining primary and secondary loss forms. It satisfies the stem's quantification constraint by expressing impact in financial terms, distinct from probability or frequency. This makes it the probable financial impact of a cyber incident.

  • ✗

    The cost of implementing security controls

    Why it's wrong here

    Control cost is a risk-mitigation input, not a FAIR loss factor; Loss Magnitude quantifies the financial impact of a threat event across the six loss forms. It is tempting because controls reduce loss exposure, but FAIR measures the loss itself, not the spend incurred preventing it.

  • ✗

    The number of records compromised in a data breach

    Why it's wrong here

    Record count is a breach metric, not a FAIR factor; Loss Magnitude is expressed in monetary terms across primary and secondary loss forms. It is tempting because volume of compromised records often correlates with cost, but FAIR requires the quantified financial impact itself, not the count driving it.

  • ✗

    The probability that a threat event will occur

    Why it's wrong here

    Threat event frequency, not Loss Magnitude, describes how often a threat agent acts against an asset. The definition is tempting because probability language pervades FAIR, but Loss Magnitude sits on the impact side of the risk equation, quantifying monetary loss per event rather than likelihood.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.