hardMultiple ChoiceObjective-mapped
CRISC Practice Question: During a risk assessment, the IT risk manager…
During a risk assessment, the IT risk manager needs to prioritize risks for treatment. Which of the following risk characteristics should be weighted MOST heavily?
⚠ Common exam trap
ISACA often tests the misconception that financial impact or likelihood should be the primary weighting factor, but CRISC emphasizes that strategic alignment is the overriding criterion because risk treatment must support the enterprise’s overall business goals, not just minimize cost or probability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The degree to which the risk affects strategic business objectives
In CRISC, risk prioritization is fundamentally driven by alignment with strategic business objectives because IT risk management exists to protect the enterprise’s mission and goals. Even a high-likelihood or high-financial-impact risk may be deprioritized if it does not materially affect the organization’s strategic objectives, as the risk treatment decision must support business value and continuity. This weighting ensures that resources are allocated to risks that most threaten the enterprise’s ability to achieve its core mission.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The degree to which the risk affects strategic business objectives
Why this is correct
Risks that impact strategic objectives are of highest priority.
- ✗
The ease of implementing mitigating controls
Why it's wrong here
Priority should be based on risk level, not ease of mitigation.
- ✗
The likelihood that the threat will be exploited
Why it's wrong here
Likelihood is important but should be considered together with impact and strategic alignment.
- ✗
The financial impact calculated in monetary terms
Why it's wrong here
Financial impact is one factor, but non-financial impacts (reputation, compliance) may be more critical.
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.