Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

In developing a risk scenario, connecting a threat event to business impact is crucial. Which of the following is the BEST example of a properly connected risk scenario?

⚠ Common exam trap

CRISC often tests the threat-to-business-impact linkage — candidates select answers that stop at technical or IT-internal consequences instead of tracing through to financial, regulatory, or reputational business impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A DDoS attack causes website unavailability for 4 hours, resulting in $500,000 lost sales and customer churn.

A properly connected risk scenario must link a specific threat event to a quantified or clearly articulated business impact. Option D does this precisely: a DDoS attack (threat event) causes website unavailability for 4 hours (operational impact) resulting in $500,000 lost sales and customer churn (financial and reputational business impact). This chain from threat to measurable business consequence is what CRISC expects in risk scenario development.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A firewall misconfiguration allows unauthorized access, causing a security incident.

    Why it's wrong here

    The scenario restates the threat as its own outcome: unauthorised access is the incident, not a business impact. It tempts because firewall misconfiguration is a real threat event, and this phrasing would suit a scenario whose endpoint is a security breach rather than business consequence.

  • ✗

    A ransomware attack encrypts files, leading to IT department overtime.

    Why it's wrong here

    Overtime is an IT operational cost, not a business impact, so the scenario stops short of connecting the threat to consequence. It tempts because ransomware genuinely drives recovery effort, and overtime would fit a scenario scoped to IT resource strain rather than enterprise impact.

  • ✗

    An insider steals data, leading to legal fees.

    Why it's wrong here

    Legal fees are a plausible impact, but the scenario omits which data, whose data and the resulting business consequence, leaving the threat-impact link underspecified. It tempts because insider theft with legal cost is realistic, and would qualify where the stem asked only for a threat paired with any impact.

  • ✓

    A DDoS attack causes website unavailability for 4 hours, resulting in $500,000 lost sales and customer churn.

    Why this is correct

    This scenario chains a specific threat event (DDoS attack) to a measurable operational consequence (four hours of website unavailability) and then to quantified business impact ($500,000 lost sales plus customer churn), demonstrating the causal linkage the stem demands.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.