CRISC IT Risk Identification Practice Question
Which THREE of the following are common business impact categories used in risk scenarios?
⚠ Common exam trap
CRISC often tests the distinction between business impact categories and technical or strategic-level factors, tempting candidates to select operational issues like technical downtime or strategic misalignment as impact categories.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reputational damage
Reputational damage (A) is a standard business impact category because risk scenarios assess how incidents such as data breaches or outages harm customer trust, brand image, and market standing. Financial loss (B) is universally used in risk scenarios to quantify direct and indirect monetary effects like lost revenue, remediation costs, and reduced shareholder value. Regulatory penalty (D) is also a common business impact category, covering fines, sanctions, and legal enforcement actions imposed by bodies such as GDPR or HIPAA regulators when compliance obligations are breached. Strategic misalignment (C) is not typically treated as a business impact category in risk scenarios; it is more of a governance or planning concern than a measurable consequence of a realized risk. Technical downtime (E) is an operational/technical effect or cause rather than a business impact category, since it is usually translated into business consequences such as financial loss or reputational damage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Reputational damage
Why this is correct
Reputational damage is a standard business impact category in risk scenarios, capturing loss of customer trust, brand value and market standing. It is assessed alongside financial, operational and regulatory impacts when quantifying the consequences of an IT risk event.
- ✓
Financial loss
Why this is correct
Financial loss is a core business impact category because risk scenarios must express consequences in monetary terms, enabling quantification of potential revenue, asset or remediation costs. It satisfies the stem's requirement for common impact categories by translating technical events into measurable business outcomes leadership can prioritise and compare.
- ✗
Strategic misalignment
Why it's wrong here
Strategic misalignment concerns whether initiatives support objectives, an IT or governance risk theme rather than a business impact category. Impact categories are financial, reputational, regulatory, legal and operational. Strategic misalignment fits risk-identification workshops mapping threats to objectives, not impact quantification.
- ✓
Regulatory penalty
Why this is correct
Regulatory penalty is a recognised business impact category because risk scenarios must capture consequences beyond money, such as fines, sanctions or compliance enforcement. It satisfies the stem's requirement for common impact categories by linking technical events to legal and regulatory exposure that affects the organisation's operating licence.
- ✗
Technical downtime
Why it's wrong here
Technical downtime describes an IT availability metric, not a business impact category. Risk scenarios use financial, reputational, regulatory, legal and operational categories expressed in business terms. Technical downtime belongs in the likelihood or control-assessment discussion, where infrastructure reliability metrics are quantified.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.