Courseiva
IT Risk Identification →mediumMultiple Select

CRISC IT Risk Identification Practice Question

Which THREE of the following are common consequences in an IT risk scenario?

⚠ Common exam trap

The trap here is that candidates see plausible-sounding business terms like 'increased market share' and 'employee satisfaction' and select them because they sound like outcomes — but CRISC requires recognizing that risk consequences must be negative impacts, not benefits or neutral metrics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Financial loss

In IT risk scenarios, a common consequence is financial loss (A), because incidents such as data breaches, downtime, or fraud directly incur remediation costs, lost revenue, and legal fees. A regulatory penalty (D) is also a standard consequence, since failures to comply with laws or standards like GDPR, HIPAA, or PCI DSS can result in fines and sanctions. Reputational damage (E) is likewise a typical consequence, as publicized security or availability failures erode customer trust and brand value. By contrast, increased market share (B) and employee satisfaction (C) are generally positive business outcomes, not consequences of risk events, so they do not belong in this list.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Financial loss

    Why this is correct

    Financial loss is a standard business consequence recorded when an IT risk materialises, directly satisfying the stem's requirement for common risk outcomes. It captures monetary impact from downtime, remediation, regulatory penalties or lost revenue, and is a core input to CRISC risk analysis and response decisions.

  • ✗

    Increased market share

    Why it's wrong here

    Increased market share is a positive business outcome, whereas risk consequences are negative effects on objectives. It tempts because risk treatment can indirectly support growth, but the scenario consequence itself must describe harm such as revenue loss, fines or operational disruption.

  • ✗

    Employee satisfaction

    Why it's wrong here

    Employee satisfaction is an internal morale measure, not a consequence arising from a risk event affecting objectives. It tempts because workforce factors influence risk likelihood, but consequences in risk scenarios are outcomes such as financial loss, regulatory penalty or reputational damage.

  • ✓

    Regulatory penalty

    Why this is correct

    A regulatory penalty is a direct consequence arising from an IT risk event, such as a data breach or compliance failure, resulting in fines or sanctions. It represents the financial and legal impact the organisation incurs once the risk materialises.

  • ✓

    Reputational damage

    Why this is correct

    Reputational damage is a consequence of an IT risk event, reflecting lost customer trust, brand harm and reduced business following a breach or outage. It captures the intangible, often long-lasting impact that persists after the technical incident is resolved.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.