CRISC IT Risk Assessment Practice Question
In a qualitative risk assessment, which TWO elements are typically used to determine the risk rating?
⚠ Common exam trap
It's easy for candidates to confuse the inputs for inherent risk rating (likelihood and impact) with factors used in residual risk calculation or risk treatment decisions, such as control effectiveness or cost of mitigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Likelihood
In a qualitative risk assessment, risk rating is determined by combining the likelihood of a threat occurring with the impact of that threat on business objectives. Likelihood (A) and impact (B) are the two fundamental elements used in a risk matrix to assign a qualitative rating such as high, medium, or low. This approach relies on subjective judgment rather than numerical data, making it suitable for scenarios where precise quantification is not feasible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Likelihood
Why this is correct
Likelihood is one of the two axes in a qualitative risk assessment, paired with impact, to derive the overall risk rating. It expresses the probability that a given threat will exploit a vulnerability, directly satisfying the stem's requirement for the elements used to determine that rating.
- ✓
Impact
Why this is correct
Impact estimates the magnitude of loss or harm if the risk event occurs, forming one axis of the qualitative rating. Combined with likelihood on a defined scale, it produces the risk rating used for prioritisation.
- ✗
Risk appetite
Why it's wrong here
Risk appetite is a governance threshold applied when deciding responses, not an input to the likelihood-by-impact rating itself. It is tempting because appetite frames how much risk is tolerable, and it would be the correct reference when prioritising remediation or accepting residual risk after ratings are calculated.
- ✗
Cost of mitigation
Why it's wrong here
Cost of mitigation is a response-planning consideration, not an element of the likelihood and impact combination that produces the rating. It is tempting because cost drives treatment decisions, and it would be correct when performing a cost-benefit analysis to justify or reject a proposed risk response.
- ✗
Control effectiveness
Why it's wrong here
Control effectiveness adjusts residual risk after inherent rating, so it is not one of the two elements multiplied to produce the qualitative rating. It is tempting because controls clearly influence risk, and it would be correct when assessing residual risk or evaluating whether existing mitigations reduce exposure sufficiently.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.