Courseiva
hardMultiple ChoiceObjective-mapped

CRISC Practice Question: During a risk assessment, the IT risk manager…

During a risk assessment, the IT risk manager needs to prioritize risks for treatment. Which of the following risk characteristics should be weighted MOST heavily?

⚠ Common exam trap

ISACA often tests the misconception that financial impact or likelihood should be the primary weighting factor, but CRISC emphasizes that strategic alignment is the overriding criterion because risk treatment must support the enterprise’s overall business goals, not just minimize cost or probability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The degree to which the risk affects strategic business objectives

In CRISC, risk prioritization is fundamentally driven by alignment with strategic business objectives because IT risk management exists to protect the enterprise’s mission and goals. Even a high-likelihood or high-financial-impact risk may be deprioritized if it does not materially affect the organization’s strategic objectives, as the risk treatment decision must support business value and continuity. This weighting ensures that resources are allocated to risks that most threaten the enterprise’s ability to achieve its core mission.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The degree to which the risk affects strategic business objectives

    Why this is correct

    Risks that impact strategic objectives are of highest priority.

  • The ease of implementing mitigating controls

    Why it's wrong here

    Priority should be based on risk level, not ease of mitigation.

  • The likelihood that the threat will be exploited

    Why it's wrong here

    Likelihood is important but should be considered together with impact and strategic alignment.

  • The financial impact calculated in monetary terms

    Why it's wrong here

    Financial impact is one factor, but non-financial impacts (reputation, compliance) may be more critical.

About these practice questions

One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.