hardMultiple Select
CRISC Practice Question: Which THREE factors should be considered when…
Which THREE factors should be considered when determining the likelihood of a threat exploiting a vulnerability?
⚠ Common exam trap
Many candidates confuse factors that determine likelihood (probability of occurrence) with factors that determine impact (consequences), leading candidates to incorrectly select asset value or regulatory fines as likelihood inputs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ease of exploitation
Option A (Ease of exploitation) is correct because the likelihood of a threat exploiting a vulnerability depends heavily on how simple the attack is to execute — for example, whether a public exploit exists, whether it requires authentication, or whether it can be triggered remotely versus requiring local access. Option D (Existing controls) is correct because compensating and preventive controls such as firewalls, EDR, MFA, and patching directly reduce the probability that a vulnerability can be successfully exploited. Option E (Threat actor capability) is correct because likelihood is a function of the adversary's skill, resources, motivation, and tooling — a sophisticated, well-funded actor is far more likely to exploit a given weakness than an unskilled one. Option B (Regulatory fines) is not a likelihood factor; it is a potential business impact or consequence of a breach, which belongs to the impact side of risk analysis. Option C (Asset value) is also an impact-side consideration, describing how much a compromised asset is worth to the organization, not how probable exploitation is.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ease of exploitation
Why this is correct
Ease of exploitation directly quantifies how readily a threat actor can leverage a weakness, which is a core likelihood input. A vulnerability requiring trivial effort, such as a default credential, raises likelihood; one demanding specialised access or complex chaining lowers it. This satisfies the stem's likelihood determination constraint.
- ✗
Regulatory fines
Why it's wrong here
Regulatory fines are a consequence of a realised risk, quantifying impact rather than likelihood. They belong in impact assessment or risk-response budgeting, whereas likelihood factors concern threat capability, motivation and the exposure or exploitability of the vulnerability itself.
- ✗
Asset value
Why it's wrong here
Asset value drives the magnitude of loss if a vulnerability is exploited, so it feeds impact analysis, not likelihood. Likelihood instead depends on threat capability, intent and the ease of exploiting the specific vulnerability, independent of what the asset is worth.
- ✓
Existing controls
Why this is correct
Existing controls directly reduce exploit likelihood by blocking or detecting the threat's attack path, so their strength and coverage determine whether a vulnerability remains reachable. This satisfies the stem's likelihood factor: residual exposure after mitigation, not inherent vulnerability severity, drives how probable successful exploitation actually is.
- ✓
Threat actor capability
Why this is correct
Threat actor capability directly determines whether an adversary possesses the skill, tools and resources to exploit a specific weakness. A highly capable actor raises exploitation likelihood, whereas an unskilled one lowers it. This satisfies the stem's requirement to assess likelihood factors, since capability is a core input to that judgement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.