Courseiva
IT Risk Identification →mediumMultiple Select

CRISC IT Risk Identification Practice Question

Which THREE of the following are common business impact categories used in risk scenarios?

⚠ Common exam trap

CRISC often tests the distinction between business impact categories and technical or strategic-level factors, tempting candidates to select operational issues like technical downtime or strategic misalignment as impact categories.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reputational damage

Reputational damage (A) is a standard business impact category because risk scenarios assess how incidents such as data breaches or outages harm customer trust, brand image, and market standing. Financial loss (B) is universally used in risk scenarios to quantify direct and indirect monetary effects like lost revenue, remediation costs, and reduced shareholder value. Regulatory penalty (D) is also a common business impact category, covering fines, sanctions, and legal enforcement actions imposed by bodies such as GDPR or HIPAA regulators when compliance obligations are breached. Strategic misalignment (C) is not typically treated as a business impact category in risk scenarios; it is more of a governance or planning concern than a measurable consequence of a realized risk. Technical downtime (E) is an operational/technical effect or cause rather than a business impact category, since it is usually translated into business consequences such as financial loss or reputational damage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Reputational damage

    Why this is correct

    Reputational damage is a standard business impact category in risk scenarios, capturing loss of customer trust, brand value and market standing. It is assessed alongside financial, operational and regulatory impacts when quantifying the consequences of an IT risk event.

  • ✓

    Financial loss

    Why this is correct

    Financial loss is a core business impact category because risk scenarios must express consequences in monetary terms, enabling quantification of potential revenue, asset or remediation costs. It satisfies the stem's requirement for common impact categories by translating technical events into measurable business outcomes leadership can prioritise and compare.

  • ✗

    Strategic misalignment

    Why it's wrong here

    Strategic misalignment concerns whether initiatives support objectives, an IT or governance risk theme rather than a business impact category. Impact categories are financial, reputational, regulatory, legal and operational. Strategic misalignment fits risk-identification workshops mapping threats to objectives, not impact quantification.

  • ✓

    Regulatory penalty

    Why this is correct

    Regulatory penalty is a recognised business impact category because risk scenarios must capture consequences beyond money, such as fines, sanctions or compliance enforcement. It satisfies the stem's requirement for common impact categories by linking technical events to legal and regulatory exposure that affects the organisation's operating licence.

  • ✗

    Technical downtime

    Why it's wrong here

    Technical downtime describes an IT availability metric, not a business impact category. Risk scenarios use financial, reputational, regulatory, legal and operational categories expressed in business terms. Technical downtime belongs in the likelihood or control-assessment discussion, where infrastructure reliability metrics are quantified.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.