Courseiva

CRISC · domain

IT Risk Assessment

This domain covers IT risk assessment: identifying, analyzing, and evaluating risk using qualitative and quantitative methods. You must calculate ALE from SLE and ARO, interpret inherent versus residual risk, select risk treatment options, and distinguish preventive, detective, and corrective controls. Questions test practical application of risk concepts to business scenarios.

169 questions39 easy82 medium48 hard

Focused practice

Practice IT Risk Assessment questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about IT Risk Assessment

You must calculate ALE from SLE and ARO, interpret inherent versus residual risk, and select appropriate risk treatments and control types. The single most important thing is to correctly apply the risk assessment formulas and definitions to scenario-based questions.

Calculating ALE using SLE × ARO for a given risk scenario

Classifying risk treatment: avoid, mitigate, transfer, accept

Differentiating inherent risk from residual risk after controls

Identifying detective controls that detect risk events after occurrence

Watch out for

Common IT Risk Assessment exam traps

  • ▸Confusing risk transfer (e.g., insurance) with risk mitigation, which reduces likelihood or impact through controls.
  • ▸Miscalculating ALE by using incorrect ARO or SLE values, or mixing up annualized loss expectancy with single loss expectancy.
  • ▸Assuming residual risk is always lower than inherent risk, ignoring that controls can be ineffective or introduce new risks.

Question index

All IT Risk Assessment questions (169)

Click any question to see the full explanation, or start a practice session above.

1

A risk assessment identifies a critical vulnerability in a web application. Which control type would be most effective in preventing exploitation of this vulnerability?

Medium
2

An organization assesses a risk and determines the inherent risk score is 20 (critical). After implementing controls, the residual risk score is 8 (medium). What does this indicate about the controls?

Hard
3

Which of the following is a detective control?

Easy
4

A risk practitioner is reviewing the risk register and notices that several risks have not been reassessed in over a year. The business environment has changed significantly due to a new regulation. What is the PRIMARY reason the practitioner should escalate this issue to the risk committee?

Medium
5

An organization uses a 5×5 risk heat map to assess IT risks. Which of the following is the PRIMARY advantage of this qualitative approach?

Easy
6

A retail company is conducting a risk assessment for its point-of-sale (POS) systems. The risk team determines that the inherent risk of a malware attack is high. The company implements endpoint detection and response (EDR) tools and network segmentation. After these controls, the risk is re-evaluated. What is this re-evaluated risk called?

Easy
7

An organization decides to outsource its data center operations to a cloud provider with strict contractual penalties for security breaches. This is an example of which risk treatment option?

Medium
8

In the FAIR framework, loss magnitude (LM) is composed of primary loss and secondary loss. Which of the following is an example of secondary loss?

Hard
9

A risk analyst is assessing a newly discovered vulnerability in an internet-facing server. The analyst collects several data points: the vulnerability has a CVSS base score of 9.8, there are known exploits in the wild, and the server is critical for processing customer transactions. However, the organization's intrusion detection system has a signature that blocks the specific exploit, and the server is patched monthly. The analyst must determine the risk level. Which of the following should the analyst use to BEST assess the risk?

Medium
10

During an IT risk assessment, a risk owner identifies a risk that is within the organization's risk appetite. The recommended risk treatment option is to:

Medium
11

A risk analyst is building a risk register for a newly deployed customer relationship management (CRM) system that stores personally identifiable information (PII). The analyst needs to document the risk that an attacker could exfiltrate the PII database. Which of the following BEST represents the threat component of this risk statement?

Medium
12

An organization is assessing control effectiveness for a firewall. Which THREE factors should be evaluated to determine control effectiveness? (Select THREE)

Hard
13

In assessing control effectiveness, an IS auditor evaluates both design adequacy and operating effectiveness. Which of the following indicates that a control is operating effectively?

Medium
14

A risk manager is using a 5×5 likelihood-impact matrix to assess a set of identified risks. What is the PRIMARY advantage of using this qualitative method?

Easy
15

A financial services firm is evaluating the risk of insider threat in its trading department. The risk team has identified that a small number of traders have elevated privileges that allow them to execute trades and access sensitive market data. The team must determine the MOST effective control to reduce the likelihood of unauthorized trading activity. Which control should they prioritize?

Hard
16

A multinational manufacturer is assessing the risk of a ransomware attack on its operational technology (OT) network. The risk team has identified that the OT network is segmented from the corporate IT network, but a shared jump server allows administrators to move between them. The team must determine the MOST significant factor that could increase the likelihood of ransomware spreading from IT to OT. Which factor should they prioritize?

Hard
17

A risk assessment of a critical financial application identifies a high inherent risk due to outdated software. The risk manager is considering mitigation options. Which TWO of the following would be considered preventive controls?

Medium
18

A healthcare provider is conducting a risk assessment for its electronic health record (EHR) system. The risk team has identified that a recent upgrade introduced a new vulnerability that could allow unauthorized access to patient data. The vulnerability has a known exploit but no patch is available yet. The team must decide on the BEST immediate risk response. What should they do FIRST?

Medium
19

A multinational corporation is conducting a risk assessment for its third-party vendors. The risk team has assigned a high inherent risk rating to a vendor that provides critical payroll processing. The vendor has recently provided a SOC 2 Type II report with no exceptions, and the contract includes a right-to-audit clause. The risk practitioner must determine the residual risk rating. Which factor is MOST important in making this determination?

Hard
20

A risk assessment team is prioritizing IT risks for treatment. Which THREE factors should be considered when prioritizing risks? (Select THREE)

Hard
21

A company is evaluating control types for a new system. The security team proposes implementing an intrusion detection system (IDS) and a backup restoration process. Which TWO control types do these represent, respectively?

Medium
22

A risk practitioner is assessing a cloud-hosted payroll application. The vendor's SOC 2 report shows effective controls, but the report covers only the period ending eight months ago, and the vendor has since migrated to a new hosting region. The practitioner needs to determine whether the control environment can still be relied upon. Which of the following is the MOST appropriate next step?

Hard
23

During an IT risk assessment, the risk owner identifies a high inherent risk for a legacy system. After implementing a firewall and intrusion detection system, the residual risk is calculated. Which of the following best describes residual risk?

Medium
24

An organization is performing a quantitative risk analysis using the FAIR framework. Which THREE of the following are direct components of the FAIR model?

Hard
25

A risk analyst at a healthcare provider is assessing the risk of a ransomware attack on a clinical data repository. The analyst estimates that a ransomware event would cost $800,000 in recovery and downtime, and that such an event is likely to occur once every four years. What is the annualized loss expectancy (ALE) for this risk?

Medium
26

A global investment firm maintains a central risk register. The CISO wants to reduce the number of entries by consolidating risks that share the same root cause. Which action BEST supports this goal while preserving the risk register's integrity?

Medium
27

A retail company is assessing risk for a legacy point-of-sale system that cannot be patched. The risk team wants to identify controls that would reduce the likelihood of a successful exploitation of known vulnerabilities on these terminals. Which TWO of the following are preventive controls that would BEST reduce the likelihood of exploitation? (Choose two.)

Hard
28

A financial services firm has completed a risk assessment of its trading platform. The chief risk officer wants to ensure the assessment results are comparable across business units and that the reasoning behind each likelihood and impact rating is transparent to auditors. Which action BEST supports this objective?

Medium
29

During an IT risk assessment, the risk owner decides to accept a risk that falls within the organization's risk appetite. Which of the following actions is most appropriate for the risk owner to take?

Easy
30

A risk analyst is building a scenario for a ransomware event affecting a hospital's electronic health record environment. The analyst wants to capture loss magnitude dimensions that are frequently overlooked when only direct recovery costs are counted. Which TWO loss factors should be included to make the magnitude estimate more complete? (Choose two.)

Medium
31

Which type of control is designed to reduce the likelihood of a risk event occurring?

Easy
32

An organization is considering outsourcing its payroll processing to a third party. The risk assessment shows that the inherent risk of payroll errors is high, but the vendor contract includes liability clauses and the organization obtains cyber insurance. This risk treatment is best described as:

Hard
33

A company is considering risk transfer for a new IT project. Which TWO options represent valid risk transfer mechanisms? (Select TWO)

Medium
34

A risk practitioner is using a 5×5 heat map to assess IT risks. Which of the following is the primary advantage of this qualitative approach?

Easy
35

A healthcare organization is assessing risks to its electronic health record (EHR) system. The risk team is evaluating the likelihood of a threat event. Which TWO factors are MOST relevant when estimating the likelihood of a threat exploiting a vulnerability? (Choose two.)

Medium
36

A risk assessment identifies a threat with high likelihood and high impact. The risk owner proposes transferring the risk via cyber insurance. However, the insurance policy has a high deductible and excludes certain attack types. Which THREE of the following should be considered when evaluating the effectiveness of this risk transfer?

Hard
37

An organization identifies a risk that is within its risk appetite. The risk owner decides to formally document the risk and accept it without implementing additional controls. Which of the following is required for this risk acceptance?

Medium
38

An organization is assessing control effectiveness for a key process. Which TWO aspects should be evaluated to determine if a control is effective?

Medium
39

A software development company is assessing the risk of a data breach in its cloud-based source code repository. The risk assessment team has identified that the repository contains proprietary algorithms and customer data. The team is considering implementing a control that would encrypt the data at rest. Which of the following BEST describes the impact of this control on the risk?

Hard
40

A financial services firm is performing an IT risk assessment on its legacy 3270-based transaction processing system. The system has no vendor support, no documentation, and only two remaining staff members who understand its internals. The risk committee asks the risk analyst to determine the MOST appropriate way to characterize the risk associated with this asset. Which of the following should the analyst do FIRST?

Medium
41

An organization is evaluating risks and decides to purchase cyber insurance to cover potential financial losses from data breaches. Which risk treatment option does this represent?

Medium
42

A healthcare organization is assessing the risk of a ransomware attack on its electronic health record (EHR) system. The risk assessment team has identified that the likelihood of an attack is high due to recent industry trends, and the impact would be severe, including patient safety risks and regulatory fines. The organization has a limited budget and wants to implement controls that provide the greatest risk reduction. Which of the following risk response strategies is MOST appropriate in this scenario?

Hard
43

A risk manager uses a 5x5 heat map to plot the likelihood and impact of identified risks. This approach is an example of which type of risk analysis?

Easy
44

A retail company is conducting an IT risk assessment for its point-of-sale (POS) system. The risk team has identified several threats, including malware, insider theft, and denial-of-service (DoS) attacks. The company currently uses antivirus software, firewalls, and role-based access controls. Which TWO of the following are the MOST appropriate risk response actions to address the identified threats? (Choose two.)

Medium
45

A financial services firm is conducting an IT risk assessment on a legacy trading application. The assessment team wants to prioritize risks based on the combination of the likelihood of a threat event and the magnitude of its impact. The firm has limited resources and needs to focus on the most significant risks first. Which of the following BEST describes the purpose of using a risk map (heat map) in this context?

Medium
46

An insurance company is assessing the risk of a distributed denial-of-service (DDoS) attack against its customer portal. The risk team estimates that a threat actor group has both the capability and the intent to launch such an attack, and that the portal has an unpatched vulnerability that could be exploited to amplify the attack. Which factor does the unpatched vulnerability PRIMARILY represent in this risk scenario?

Medium
47

During a quantitative risk analysis, the risk team calculates the loss event frequency (LEF) using the FAIR framework. If the threat event frequency (TEF) is 10 per year and the vulnerability (V) is 0.3, what is the LEF?

Hard
48

A retail company is prioritizing risks for the coming year. Management wants to focus resources where the potential financial loss is greatest, but the risk team has only ordinal likelihood and impact ratings. Which approach BEST supports this prioritization?

Medium
49

A risk assessment team is prioritizing risks for treatment using inherent risk ratings. Which TWO factors should be considered when deciding which risks to treat first?

Medium
50

A retail company is conducting a risk assessment for its point-of-sale (POS) system. The risk team has identified several factors that could affect the likelihood of a data breach. Which TWO factors are considered threat event frequency components that increase the likelihood of a breach? (Choose two.)

Medium
51

Which of the following best describes residual risk?

Easy
52

A healthcare organization is assessing the risk of a ransomware attack on its electronic health record (EHR) system. The risk team has identified that the organization performs daily incremental backups and weekly full backups, but the backups are stored on the same network share as the EHR data. The risk owner argues that the backup strategy reduces the impact of a ransomware attack. Which statement BEST describes the residual risk after considering this control?

Hard
53

A risk assessment identifies a high-likelihood, high-impact risk associated with a legacy system. The business owner decides to decommission the system to eliminate the risk. Which risk treatment option is being applied?

Medium
54

A newly appointed risk owner is reviewing a risk register entry for an aging payroll application. The entry shows a likelihood rating, an impact rating, an inherent risk score, and a residual risk score, but no owner signature or review date. Which action should the risk practitioner take FIRST to strengthen the register's usefulness for IT risk assessment?

Easy
55

A risk analyst at a regional bank is assessing the risk to its core banking platform. The analyst finds that the platform has a known vulnerability with a high exploitability score, but the platform is isolated on a segmented network with no external connectivity and strict change control. The analyst must determine the PRIMARY factor that reduces the likelihood of exploitation. Which factor should the analyst emphasize?

Medium
56

In the FAIR model, 'Loss Event Frequency' is calculated as:

Hard
57

An organization is conducting a risk assessment and finds that the inherent risk for a critical asset is very high due to a high threat event frequency and high vulnerability. The current controls are assessed as adequate in design but not operating effectively. Which THREE of the following should be considered when calculating residual risk?

Hard
58

A risk analyst is evaluating a critical customer database. The asset value is $2,000,000; the exposure factor if the database is compromised is 40%. The annualized rate of occurrence (ARO) for a successful breach is estimated at 0.25. What is the annualized loss expectancy (ALE)?

Medium
59

An organization uses the FAIR framework to calculate annualized loss expectancy (ALE) for a specific risk. Given that the single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 0.2, what is the ALE?

Medium
60

A financial services firm is performing an IT risk assessment on a legacy trading platform. The risk team has identified several weaknesses in the platform's patch management process. Which TWO of the following are examples of vulnerabilities that should be recorded in the risk register? (Choose two.)

Hard
61

A risk manager is using a 5x5 heat map to assess IT risks. Which of the following best describes the primary limitation of this qualitative risk analysis approach?

Easy
62

Which of the following best describes the primary limitation of qualitative risk analysis?

Medium
63

A quantitative risk analysis using FAIR requires estimating which THREE primary factors?

Hard
64

When prioritizing risk treatment actions, which of the following should be the primary consideration?

Medium
65

A risk analyst is assessing the impact of a potential ransomware attack. Which THREE categories of business impact should be considered?

Medium
66

Which of the following is an example of a detective control in IT risk management?

Easy
67

A risk manager decides to accept a risk because the cost of controls exceeds the potential loss. Which of the following is required for this risk treatment option?

Medium
68

In a qualitative risk assessment, which TWO elements are typically used to determine the risk rating?

Easy
69

A risk practitioner is facilitating a risk assessment workshop for a new cloud-based HR system. The team is identifying threats. Which TWO of the following are examples of threat events that should be considered? (Choose two.)

Medium
70

In a qualitative risk assessment, a risk owner argues that the likelihood of a cyberattack is low because the organization has strong perimeter defenses. However, the analyst notes that the impact would be catastrophic. Which limitation of qualitative analysis is most relevant?

Medium
71

An organization is evaluating risk treatment options for a critical vulnerability. Which TWO options would be considered risk mitigation?

Medium
72

Which risk treatment option is being used when an organization decides to stop a business activity that creates a high-risk exposure?

Easy
73

An IT risk manager is reviewing the risk register and finds that the same database server appears in three separate risk entries: one for unauthorized access, one for data corruption, and one for denial of service. What is the PRIMARY benefit of structuring the register this way rather than combining all three into a single entry?

Easy
74

An organization is considering purchasing cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment option?

Medium
75

An organization is evaluating the risk of a data breach using the FAIR framework. Which of the following components is part of Loss Event Frequency (LEF)?

Easy
76

A small logistics company has no formal risk assessment process. The new IT manager wants to introduce a simple, repeatable method to identify and evaluate IT risks. Which action should the manager take FIRST?

Easy
77

In the FAIR framework, which of the following correctly represents the calculation of Loss Event Frequency (LEF)?

Hard
78

When performing a risk assessment, which TWO of the following are components of inherent risk?

Easy
79

A financial services firm is completing its annual IT risk assessment. The CISO wants to compare the relative severity of 40 identified risks across different business units and prioritize which ones to treat first. The risk team has limited quantitative data and needs a consistent, repeatable method that reflects both likelihood and impact. Which approach BEST meets this need?

Hard
80

A retail company is assessing the risk of a point-of-sale (POS) system compromise. The risk team estimates that a successful attack would cost $500,000 in fines, remediation, and lost sales. The likelihood of such an attack in the next year is estimated at 20%. What is the annualized loss expectancy (ALE) for this risk scenario?

Easy
81

A risk practitioner is assessing a new e-commerce platform. The business owner insists that the platform must be available 24/7. The practitioner identifies that a distributed denial-of-service (DDoS) attack could cause an outage. Which of the following BEST describes the risk scenario?

Hard
82

A company's risk assessment identifies that a threat actor has high capability and motivation to exploit a vulnerability. Which factor does this relate to?

Medium
83

A multinational bank is assessing risk for a new mobile banking feature that stores limited customer data on devices. The risk team must decide whether to use a qualitative or quantitative approach. Which of the following is the MOST important factor in making this decision?

Hard
84

A financial services company is conducting a risk assessment for a new mobile banking application. The risk team identifies that the application will store sensitive customer data on the device. The team must determine the appropriate risk response. The CISO suggests implementing encryption and tokenization to protect the data. The business sponsor argues that these controls will delay the launch and increase costs. The risk owner must decide how to proceed. Which of the following is the MOST appropriate action for the risk owner to take?

Hard
85

Which of the following is a detective control for an information system?

Easy
86

An organization calculated the inherent risk for a critical system as 'High' using a 5x5 heat map. After implementing controls, the residual risk is assessed as 'Medium'. What does this indicate about the control effectiveness?

Hard
87

An organization has implemented a firewall (preventive), intrusion detection system (detective), and a backup restoration plan (corrective) to address a specific risk. The risk manager assesses the control effectiveness as follows: design adequacy is strong, but operating effectiveness is weak due to inconsistent patching. Which of the following best describes the residual risk?

Hard
88

Which risk treatment option involves purchasing cyber insurance?

Easy
89

After implementing a set of controls, the risk owner calculates the residual risk. Which of the following is true about residual risk?

Medium
90

An enterprise risk analyst is aggregating risk data from three business units that each used a different likelihood scale: Unit A used a 1-3 scale, Unit B used a 1-5 scale, and Unit C used a 1-10 scale. Before consolidating results into the enterprise risk register, which action BEST ensures the aggregated risk ratings remain meaningful for management reporting?

Medium
91

Which control type is primarily focused on identifying that a risk event has occurred?

Medium
92

A quantitative risk analysis for a data breach yields an Annualized Loss Expectancy (ALE) of $500,000. The Single Loss Expectancy (SLE) is $100,000. What is the Annualized Rate of Occurrence (ARO)?

Medium
93

A company uses cyber insurance to cover losses from data breaches. This is an example of which risk treatment?

Hard
94

A risk manager is documenting the results of an IT risk assessment. She has identified the risk, analyzed its likelihood and impact, and evaluated existing controls. Which of the following should she do NEXT?

Easy
95

A risk analyst is evaluating the effectiveness of the organization's existing control environment for a newly identified risk involving unauthorized access to a human resources database. Which TWO of the following activities would BEST help the analyst determine whether the current controls reduce the risk to an acceptable level? (Choose two.)

Medium
96

A global manufacturer is performing an IT risk assessment for its industrial control systems (ICS). The risk team is evaluating threat sources and wants to identify factors that INCREASE the likelihood of a threat event occurring. Which TWO of the following factors increase the likelihood of a threat event? (Choose two.)

Hard
97

A retail company is assessing risk for a new customer loyalty application. The risk team determines that the inherent risk is high, then evaluates existing controls and finds that the residual risk is within the organization's risk appetite. The CIO asks what the residual risk rating represents. Which statement BEST describes residual risk in this context?

Medium
98

A risk assessment report includes both inherent and residual risk ratings. The inherent risk for a process is rated as 'high' based on a 5×5 heat map. After applying a set of controls, the residual risk is rated as 'medium'. What does this indicate about the control effectiveness?

Medium
99

A company is prioritizing risk treatment actions. Which THREE factors should be considered when prioritizing risks?

Medium
100

An organization is evaluating whether to accept a risk. Which TWO conditions must be met for risk acceptance to be appropriate?

Medium
101

A financial services firm is conducting an IT risk assessment for its customer-facing mobile banking application. The risk team has identified that the application's authentication mechanism relies on a third-party single sign-on (SSO) provider. During a workshop, the risk owner states that the likelihood of a breach is low because the SSO provider has a strong security reputation. However, the risk team notes that no service-level agreement (SLA) exists with the provider. Which risk factor is MOST directly affected by the absence of an SLA, and how should the risk practitioner proceed?

Medium
102

An energy utility is assessing risk to its industrial control system (ICS) network. The risk analyst discovers that the same risk scenario is rated as high risk by the operations team using a qualitative heat map and as low risk by the enterprise risk team using a quantitative model. Both teams used the same underlying data. Which of the following is the MOST likely explanation for the discrepancy?

Hard
103

In a quantitative risk analysis using FAIR, which of the following best represents Loss Magnitude (LM)?

Medium
104

A company is considering outsourcing its data center operations to a cloud provider. Which risk treatment option is the company primarily exercising?

Medium
105

An organization decides to discontinue a high-risk business process that cannot be effectively mitigated. This is an example of which risk treatment option?

Easy
106

A risk analyst uses a 5x5 heat map to evaluate a set of IT risks. For a particular risk, the likelihood is rated as 4 (likely) and impact as 5 (very high). What is the resulting risk rating?

Medium
107

A risk practitioner is assessing the risk of a legacy application that supports a critical business process. The application vendor no longer provides security patches. The business cannot replace the application within the next 12 months due to budget constraints. Which of the following is the MOST appropriate risk treatment?

Hard
108

Which of the following is an example of a corrective control?

Easy
109

A risk practitioner is using a 5×5 heat map with likelihood and impact ratings. Which of the following is a key advantage of this qualitative risk analysis approach?

Easy
110

A risk practitioner is calculating the residual risk for a critical asset. Which THREE factors should be considered?

Hard
111

A risk practitioner is prioritizing IT risks for treatment. Which factor should be the PRIMARY basis for prioritization?

Medium
112

Which of the following is a limitation of qualitative risk analysis?

Easy
113

An e-commerce company is conducting an IT risk assessment for its order management system. The risk team has identified a risk that the system could fail during peak holiday traffic, causing revenue loss. The team needs to estimate the potential financial impact of this event to inform treatment decisions. Which activity is the team performing?

Easy
114

An organization is evaluating the risk of a ransomware attack. Using the FAIR framework, which of the following components directly multiplies to calculate Loss Event Frequency (LEF)?

Medium
115

After implementing controls for a high-risk IT process, the residual risk is calculated as medium. The risk owner argues that the controls are not adequate because the inherent risk was critical. Which of the following should be the primary basis for determining control adequacy?

Hard
116

In the FAIR model, which component represents the probable frequency, within a given timeframe, that a threat agent will act against an asset?

Hard
117

A risk analyst is preparing a risk register for a new customer relationship management (CRM) system hosted in a public cloud. For each identified risk, the analyst assigns a likelihood rating (1–5) and an impact rating (1–5) based on team consensus, and then multiplies the two scores to produce a risk score. Which risk assessment approach is the analyst using?

Medium
118

Which risk treatment option involves eliminating the activity that creates the risk?

Easy
119

Which control type is designed to stop a risk event from occurring?

Easy
120

A risk assessment reveals that the likelihood of a phishing attack is high, and the impact is moderate. The organization decides to implement security awareness training and email filtering. This is an example of which risk treatment?

Hard
121

A risk analyst is building a control assessment for a payment processing environment. She needs to determine whether a new control objective is adequately addressed. She has identified the control objective, the associated risk, and the control activity. Which of the following should she do NEXT to complete the control assessment?

Medium
122

A company is considering using a qualitative risk assessment approach to evaluate IT risks. Which TWO of the following are advantages of qualitative risk analysis over quantitative risk analysis?

Easy
123

Which of the following is an example of a detective control?

Medium
124

A multinational corporation is conducting a risk assessment for its supply chain. The risk team has identified a critical supplier that provides a unique component. The supplier is located in a region prone to natural disasters. The team wants to evaluate the risk and determine the appropriate risk response. Which of the following should be the FIRST step in this evaluation?

Medium
125

A company uses the FAIR model to perform a quantitative risk analysis. The threat event frequency (TEF) is estimated at 10 per year, vulnerability (V) is 0.5, and loss magnitude (LM) per event is $50,000. What is the annualized loss expectancy (ALE)?

Medium
126

A risk practitioner is reviewing the results of a risk assessment and needs to determine the risk level for a series of identified risks. The organization uses a risk matrix with likelihood and impact scales. Which of the following is the PRIMARY purpose of determining the risk level?

Easy
127

A company decides to purchase cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment option?

Medium
128

During an IT risk assessment, the risk team identifies a high inherent risk for a legacy application. The team is evaluating control options. Which THREE are considered preventive controls?

Hard
129

A risk owner decides to accept a risk because the cost of mitigation exceeds the potential loss, and the risk level is within the organization's risk appetite. What should the risk owner do next?

Medium
130

A company identifies a high inherent risk in its online payment system. After implementing a Web Application Firewall (WAF) and conducting quarterly penetration tests, the residual risk is assessed as medium. Which of the following best explains the relationship between inherent risk, controls, and residual risk?

Hard
131

A company is assessing the risk of a ransomware attack. The security team estimates the threat event frequency as 2 attacks per year, vulnerability as 0.3 (30% chance of success), primary loss as $500,000, and secondary loss as $200,000. What is the annualized loss expectancy (ALE) using the FAIR framework?

Medium
132

A risk assessment reveals a high inherent risk that is within the organization's risk appetite. The risk owner documents the risk and formally accepts it. This is an example of which risk treatment option?

Easy
133

Which TWO of the following are examples of corrective controls?

Medium
134

During an IT risk assessment, a risk owner has identified a risk with a high inherent risk score. After reviewing control effectiveness, the residual risk remains medium. The organization decides to accept the residual risk. Which TWO of the following actions should the risk owner take?

Hard
135

After implementing controls, the risk remaining is called:

Hard
136

A company is evaluating controls for a high-risk process. Which control type is designed to stop a risk event from occurring?

Medium
137

A hospital's risk team is assessing a clinical imaging archive. The team determines that a ransomware event would encrypt the archive and disrupt diagnostic services, with an estimated single-loss magnitude of $2,000,000. Existing controls reduce the likelihood of a successful attack to an estimated 0.4 occurrences per year. What is the annualized loss expectancy (ALE) for this risk?

Hard
138

A risk analyst is assessing a critical application's inherent risk. After implementing controls, the residual risk is calculated as high. The analyst determines that the control design is adequate but operating effectiveness is poor. Which factor most likely explains the high residual risk?

Hard
139

An organization is implementing controls to mitigate the risk of data exfiltration. Which TWO control types would be considered preventive? (Select TWO)

Easy
140

A financial services firm is defining the scope of its annual IT risk assessment. The board has asked the risk team to ensure the assessment covers both internal and external factors that could affect the confidentiality of customer data. Which TWO activities should the team include to meet this expectation? (Choose two.)

Hard
141

A risk practitioner is reviewing the risk register for a cloud-based customer relationship management (CRM) system. The register contains several entries, and the practitioner must identify which entries represent inherent risk rather than residual risk. Which two of the following entries are examples of inherent risk? (Choose two.)

Medium
142

An organization is using the FAIR framework to perform a quantitative risk analysis for a data breach scenario. Which TWO of the following are components of the Annualized Loss Expectancy (ALE) calculation in FAIR?

Medium
143

An organization uses a qualitative risk assessment and assigns a likelihood of '3' and impact of '4' on a 5-point scale. The heat map defines risk scores 12-25 as high. What is the risk rating?

Medium
144

A hospital's risk team is assessing a new telehealth platform. The vendor reports that its encryption module was certified two years ago. The team wants to determine whether the residual risk of relying on that module is acceptable. Which action should the team take FIRST?

Hard
145

An organization implements an intrusion detection system (IDS) to monitor for security incidents. This is an example of which type of control?

Medium
146

Which risk treatment option involves formally acknowledging the risk and taking no further action, provided the risk is within the organization's risk appetite?

Easy
147

A risk analyst is prioritizing remediation efforts across four identified risks. The analyst has likelihood and impact ratings but must also account for the speed at which each risk could materialize and the organization's ability to respond. Which concept is the analyst applying to adjust the prioritization?

Medium
148

In the FAIR framework, Loss Event Frequency (LEF) is calculated as:

Medium
149

In the FAIR framework, what does Loss Event Frequency (LEF) represent?

Medium
150

During a risk assessment, a risk is assigned a likelihood of 'High' and an impact of 'Medium' on a 5×5 heat map. What is the risk rating?

Medium
151

Which of the following is an example of a preventive control?

Easy
152

A risk practitioner is assessing a customer-facing API that processes payment tokens. The team has documented the threat community, the vulnerability, and the potential loss magnitude, but the assessment stalls because no one can agree on how often the threat would realistically attempt exploitation. Which factor is the practitioner attempting to establish to complete this scenario-based risk analysis?

Hard
153

A company is performing a qualitative risk analysis for a new cloud migration project. Which TWO of the following are recognized limitations of qualitative risk analysis?

Medium
154

A risk manager is prioritizing risks based on their inherent risk scores. Which of the following factors should be considered when prioritizing treatment actions?

Medium
155

A company is assessing the impact of a potential ransomware attack. Which TWO impact categories are considered operational impacts?

Medium
156

An organization calculates the annualized loss expectancy (ALE) for a cyber attack scenario. The single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 2. What is the ALE?

Medium
157

A multinational retailer operates point-of-sale terminals in 30 countries. During an IT risk assessment, the risk analyst notes that a single compromised terminal could expose payment card data across multiple jurisdictions, each with different breach notification laws. The CISO asks the analyst to determine the MOST appropriate risk metric to communicate this exposure to the board. Which of the following should the analyst use?

Hard
158

A risk team is assessing a legacy inventory system that supports a product line scheduled for retirement in nine months. The system has an unpatched vulnerability that cannot be remediated without breaking vendor support, and the business has confirmed it will not extend the product line. Which risk response is MOST appropriate for the remaining exposure?

Hard
159

A quantitative risk assessment for a server shows an ARO of 0.5 and SLE of $200,000. What is the ALE, and what does it imply?

Medium
160

A healthcare organization is performing a risk assessment on its electronic health record (EHR) system. The risk team has identified that a legacy interface engine transmits unencrypted patient data between two internal segments. The organization's risk appetite for data confidentiality breaches is low. The IT team proposes to accept the risk because the segments are internal and firewalls separate them from the internet. Which risk response should the risk practitioner recommend FIRST?

Hard
161

During an IT risk assessment, the risk practitioner calculates the inherent risk score for a critical application as 25 (on a 5×5 matrix). After evaluating control effectiveness, the residual risk score is 9. What can be inferred about the controls?

Medium
162

Which THREE of the following are components of Loss Magnitude in the FAIR framework?

Medium
163

A risk practitioner is facilitating a risk assessment workshop for a new cloud-based customer relationship management (CRM) system. The business owner is eager to launch the system and states that the risk assessment is unnecessary because the cloud provider is ISO 27001 certified. Which of the following is the MOST appropriate response from the risk practitioner?

Easy
164

In a qualitative risk assessment using a 5x5 heat map, an IT risk is rated with likelihood 4 and impact 5. According to typical heat map conventions (5=Critical, 4=High, 3=Medium, 2=Low, 1=Informational), what is the overall risk rating?

Hard
165

A retail company is conducting a risk assessment for its new e-commerce platform. The assessment team is identifying inherent risks and wants to ensure they consider both internal and external factors that could increase the likelihood of a risk event. Which TWO of the following are examples of external factors that can increase inherent risk? (Choose two.)

Medium
166

Which of the following is a limitation of quantitative risk analysis?

Easy
167

A software development company is assessing risks related to its cloud infrastructure. The risk team uses a qualitative approach and creates a risk register. During a review, the team notices that a risk related to unauthorized access to customer data has a likelihood rating of 4 (on a 5-point scale) and an impact rating of 5. The risk owner decides to implement multi-factor authentication (MFA) and role-based access control (RBAC). After implementation, the likelihood rating is reduced to 2, while impact remains 5. What is the PRIMARY purpose of updating the risk register with these new ratings?

Medium
168

A hospital's IT risk register lists a risk that its medical imaging archive could become unavailable. The risk owner has documented the risk, set a review date, and decided to take no action because the potential impact is within the hospital's risk appetite. Which risk treatment option has the risk owner selected?

Easy
169

When prioritizing risk treatment actions, which factor is most important to consider alongside the risk level?

Easy

Frequently asked questions

What does the IT Risk Assessment domain cover on the CRISC exam?
You must calculate ALE from SLE and ARO, interpret inherent versus residual risk, and select appropriate risk treatments and control types. The single most important thing is to correctly apply the risk assessment formulas and definitions to scenario-based questions.
How many questions are in this domain?
This page lists all 169 IT Risk Assessment questions in the CRISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only IT Risk Assessment questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isaca-crisc ISACA-CRISC crisc risk assessment Practice Questions