CRISC IT Risk Assessment Practice Question
In the FAIR model, which component represents the probable frequency, within a given timeframe, that a threat agent will act against an asset?
⚠ Common exam trap
Many exam-takers confuse Loss Event Frequency (LEF) with Threat Event Frequency (TEF), because LEF is the more commonly cited output in risk reports, but the question specifically asks for the frequency of the threat agent acting, not the resulting loss event.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat Event Frequency (TEF)
In the FAIR model, Threat Event Frequency (TEF) is the component that estimates how often, within a given timeframe, a threat agent (such as a hacker or malware) will initiate an action against an asset. This directly matches the question's definition of 'probable frequency that a threat agent will act against an asset.' TEF is a primary input for calculating Loss Event Frequency (LEF) and ultimately risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vulnerability
Why it's wrong here
Vulnerability in FAIR represents the probability that a threat event becomes a loss event, given the threat agent acts; it is a conditional probability, not a frequency of action. Threat Event Frequency is the component measuring how often a threat agent acts within a timeframe. Vulnerability would be the answer where the question asks about susceptibility to loss.
- ✗
Loss Event Frequency (LEF)
Why it's wrong here
Loss Event Frequency measures how often loss events occur, not the frequency of threat agent action against the asset. It is tempting because it sits directly above Threat Event Frequency in the FAIR taxonomy, but the stem describes the threat agent's action, which Threat Event Frequency represents.
- ✗
Annualized Rate of Occurrence (ARO)
Why it's wrong here
ARO is a broader concept that may include multiple threat events.
- ✓
Threat Event Frequency (TEF)
Why this is correct
Threat Event Frequency quantifies how often, within a defined timeframe, a threat agent is expected to act against an asset. It sits within the FAIR loss event frequency branch, feeding vulnerability and primary loss estimates.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.