Courseiva
IT Risk Assessment →hardMultiple Choice

CRISC IT Risk Assessment Practice Question

In the FAIR model, which component represents the probable frequency, within a given timeframe, that a threat agent will act against an asset?

⚠ Common exam trap

Many exam-takers confuse Loss Event Frequency (LEF) with Threat Event Frequency (TEF), because LEF is the more commonly cited output in risk reports, but the question specifically asks for the frequency of the threat agent acting, not the resulting loss event.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Threat Event Frequency (TEF)

In the FAIR model, Threat Event Frequency (TEF) is the component that estimates how often, within a given timeframe, a threat agent (such as a hacker or malware) will initiate an action against an asset. This directly matches the question's definition of 'probable frequency that a threat agent will act against an asset.' TEF is a primary input for calculating Loss Event Frequency (LEF) and ultimately risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Vulnerability

    Why it's wrong here

    Vulnerability in FAIR represents the probability that a threat event becomes a loss event, given the threat agent acts; it is a conditional probability, not a frequency of action. Threat Event Frequency is the component measuring how often a threat agent acts within a timeframe. Vulnerability would be the answer where the question asks about susceptibility to loss.

  • ✗

    Loss Event Frequency (LEF)

    Why it's wrong here

    Loss Event Frequency measures how often loss events occur, not the frequency of threat agent action against the asset. It is tempting because it sits directly above Threat Event Frequency in the FAIR taxonomy, but the stem describes the threat agent's action, which Threat Event Frequency represents.

  • ✗

    Annualized Rate of Occurrence (ARO)

    Why it's wrong here

    ARO is a broader concept that may include multiple threat events.

  • ✓

    Threat Event Frequency (TEF)

    Why this is correct

    Threat Event Frequency quantifies how often, within a defined timeframe, a threat agent is expected to act against an asset. It sits within the FAIR loss event frequency branch, feeding vulnerability and primary loss estimates.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.