Courseiva
IT Risk Assessment →easyMultiple Choice

CRISC IT Risk Assessment Practice Question

Which of the following is a limitation of qualitative risk analysis?

⚠ Common exam trap

CRISC often tests the misconception that qualitative analysis is unusable for compliance or requires heavy tooling, when its true limitation is subjectivity and lack of cross-organizational comparability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It provides subjective results that are not comparable across organizations.

Qualitative risk analysis relies on subjective judgment, expert opinion, and descriptive scales (e.g., High/Medium/Low), which makes results inherently subjective and difficult to compare across different organizations or even different teams. This lack of standardization and reproducibility is its primary limitation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It cannot be used for regulatory compliance.

    Why it's wrong here

    Qualitative risk analysis is routinely used to support regulatory compliance, feeding risk registers and control assessments. Its actual limitations are subjectivity, inconsistent assessor ratings and coarse granularity. The compliance objection better fits quantitative analysis, which can be harder to align to prescriptive regulatory thresholds.

  • ✓

    It provides subjective results that are not comparable across organizations.

    Why this is correct

    Qualitative analysis ranks risk using descriptive scales such as high, medium and low, derived from judgement rather than measured monetary values. Those ratings reflect each assessor's context and criteria, so results cannot be reliably benchmarked against another organisation's ratings.

  • ✗

    It requires specialized software to perform.

    Why it's wrong here

    Qualitative risk analysis is performed with scales, workshops and judgement, needing no specialised tooling; spreadsheets suffice. Its genuine limitations are subjectivity and inconsistent ratings between assessors. Specialised software is characteristic of quantitative techniques such as Monte Carlo simulation, making this a plausible but misplaced objection.

  • ✗

    It is too data-intensive and time-consuming.

    Why it's wrong here

    Qualitative analysis is fast and low-data, relying on expert judgement and scales; it is not data-intensive or time-consuming. It tempts because quantitative methods demand heavy data collection, but that is their limitation, not qualitative's; qualitative's real limits are subjectivity and lack of monetary precision.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.