Courseiva
hardMultiple Choice

CRISC Practice Question: During a risk assessment, the IT risk manager…

During a risk assessment, the IT risk manager needs to prioritize risks for treatment. Which of the following risk characteristics should be weighted MOST heavily?

⚠ Common exam trap

ISACA often tests the misconception that financial impact or likelihood should be the primary weighting factor, but CRISC emphasizes that strategic alignment is the overriding criterion because risk treatment must support the enterprise’s overall business goals, not just minimize cost or probability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The degree to which the risk affects strategic business objectives

In CRISC, risk prioritization is fundamentally driven by alignment with strategic business objectives because IT risk management exists to protect the enterprise’s mission and goals. Even a high-likelihood or high-financial-impact risk may be deprioritized if it does not materially affect the organization’s strategic objectives, as the risk treatment decision must support business value and continuity. This weighting ensures that resources are allocated to risks that most threaten the enterprise’s ability to achieve its core mission.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The degree to which the risk affects strategic business objectives

    Why this is correct

    Strategic alignment determines whether a risk threatens the organisation's core objectives, so it carries the greatest weight when prioritising treatment. Likelihood and financial impact matter, but a risk undermining strategic goals can jeopardise the entire business model, making this characteristic the dominant factor in the assessment.

  • ✗

    The ease of implementing mitigating controls

    Why it's wrong here

    Ease of implementing controls addresses treatment cost, not the exposure itself, so it cannot rank risks by severity. It is tempting because effort informs whether a control is worth deploying, and it would guide sequencing once risks are already prioritised by likelihood and impact.

  • ✗

    The likelihood that the threat will be exploited

    Why it's wrong here

    Likelihood alone omits the magnitude of loss, so a frequent but trivial exploit could outrank a rare catastrophic one. It is tempting because probability drives expected-loss calculations, and it would be the dominant weighting when impacts across the risk register are broadly equivalent.

  • ✗

    The financial impact calculated in monetary terms

    Why it's wrong here

    Monetary impact alone ignores how probable the loss is, so an improbable expensive event could outrank a near-certain moderate one. It is tempting because quantified figures allow direct comparison, and it would be the dominant weighting when likelihoods across the assessed risks are effectively equal.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.