hardMultiple Choice
CRISC Practice Question: During a risk assessment, the IT risk manager…
During a risk assessment, the IT risk manager needs to prioritize risks for treatment. Which of the following risk characteristics should be weighted MOST heavily?
⚠ Common exam trap
ISACA often tests the misconception that financial impact or likelihood should be the primary weighting factor, but CRISC emphasizes that strategic alignment is the overriding criterion because risk treatment must support the enterprise’s overall business goals, not just minimize cost or probability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The degree to which the risk affects strategic business objectives
In CRISC, risk prioritization is fundamentally driven by alignment with strategic business objectives because IT risk management exists to protect the enterprise’s mission and goals. Even a high-likelihood or high-financial-impact risk may be deprioritized if it does not materially affect the organization’s strategic objectives, as the risk treatment decision must support business value and continuity. This weighting ensures that resources are allocated to risks that most threaten the enterprise’s ability to achieve its core mission.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The degree to which the risk affects strategic business objectives
Why this is correct
Strategic alignment determines whether a risk threatens the organisation's core objectives, so it carries the greatest weight when prioritising treatment. Likelihood and financial impact matter, but a risk undermining strategic goals can jeopardise the entire business model, making this characteristic the dominant factor in the assessment.
- ✗
The ease of implementing mitigating controls
Why it's wrong here
Ease of implementing controls addresses treatment cost, not the exposure itself, so it cannot rank risks by severity. It is tempting because effort informs whether a control is worth deploying, and it would guide sequencing once risks are already prioritised by likelihood and impact.
- ✗
The likelihood that the threat will be exploited
Why it's wrong here
Likelihood alone omits the magnitude of loss, so a frequent but trivial exploit could outrank a rare catastrophic one. It is tempting because probability drives expected-loss calculations, and it would be the dominant weighting when impacts across the risk register are broadly equivalent.
- ✗
The financial impact calculated in monetary terms
Why it's wrong here
Monetary impact alone ignores how probable the loss is, so an improbable expensive event could outrank a near-certain moderate one. It is tempting because quantified figures allow direct comparison, and it would be the dominant weighting when likelihoods across the assessed risks are effectively equal.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.