CRISC Information Technology and Security Practice Question
An organization uses the FAIR (Factor Analysis of Information Risk) model to quantify cyber risk. Which of the following is the correct definition of 'Loss Magnitude' in the FAIR model?
⚠ Common exam trap
The trap is conflating Loss Magnitude with Loss Event Frequency — candidates often pick the probability-based answer because both are core FAIR terms, but only LM describes financial impact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The probable financial impact of a cyber incident
In FAIR, Loss Magnitude represents the probable financial impact resulting from a loss event — it quantifies how much money an organization would lose if a threat event materializes into a loss. It is one of the two primary factors (alongside Loss Event Frequency) that combine to produce risk. It encompasses primary and secondary loss forms across productivity, response, replacement, fines, and reputation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The probable financial impact of a cyber incident
Why this is correct
Loss Magnitude in FAIR represents the total monetary loss an organisation would incur from a single loss event, combining primary and secondary loss forms. It satisfies the stem's quantification constraint by expressing impact in financial terms, distinct from probability or frequency. This makes it the probable financial impact of a cyber incident.
- ✗
The cost of implementing security controls
Why it's wrong here
Control cost is a risk-mitigation input, not a FAIR loss factor; Loss Magnitude quantifies the financial impact of a threat event across the six loss forms. It is tempting because controls reduce loss exposure, but FAIR measures the loss itself, not the spend incurred preventing it.
- ✗
The number of records compromised in a data breach
Why it's wrong here
Record count is a breach metric, not a FAIR factor; Loss Magnitude is expressed in monetary terms across primary and secondary loss forms. It is tempting because volume of compromised records often correlates with cost, but FAIR requires the quantified financial impact itself, not the count driving it.
- ✗
The probability that a threat event will occur
Why it's wrong here
Threat event frequency, not Loss Magnitude, describes how often a threat agent acts against an asset. The definition is tempting because probability language pervades FAIR, but Loss Magnitude sits on the impact side of the risk equation, quantifying monetary loss per event rather than likelihood.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.