Courseiva
IT Risk Assessment →mediumMultiple Select

CRISC IT Risk Assessment Practice Question

Which THREE of the following are components of Loss Magnitude in the FAIR framework?

⚠ Common exam trap

The trap is confusing factors from Loss Event Frequency (vulnerability severity, threat event frequency) with components of Loss Magnitude — candidates must remember that FAIR separates frequency and magnitude, and only certain costs and impacts belong to magnitude.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reputational damage

In the FAIR (Factor Analysis of Information Risk) framework, Loss Magnitude is the probable loss resulting from a risk event and is decomposed into primary and secondary loss forms, each with six loss categories: productivity, response, replacement, fines and judgments, competitive advantage, and reputation. Option A (Reputational damage) is correct because reputation loss is one of the six secondary loss categories that make up Loss Magnitude. Option C (Incident response costs) is correct because response costs — the expense of managing an incident (forensics, communications, management time) — are one of the six loss categories within Loss Magnitude. Option D (Recovery costs) is correct because replacement/recovery costs, the expense of restoring or replacing assets after an event, are likewise one of the six Loss Magnitude categories. Option B (Vulnerability severity) is not part of Loss Magnitude; vulnerability is a factor in the Frequency/Loss Event Probability side of the FAIR ontology (resistance strength against threat capability). Option E (Threat event frequency) is not part of Loss Magnitude either; it is a primary factor under Loss Event Frequency in FAIR.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Reputational damage

    Why this is correct

    Reputational damage is a secondary loss factor within FAIR's Loss Magnitude, capturing downstream consequences beyond primary response costs. It satisfies the stem's requirement by representing a distinct loss form (secondary) that organisations must quantify alongside productivity and response losses when assessing risk.

  • ✗

    Vulnerability severity

    Why it's wrong here

    Vulnerability severity belongs to Loss Event Frequency, describing how likely a threat agent's action succeeds against a control weakness. It is tempting because severity sounds quantitative, and would be correct when assessing the probability component of the FAIR risk equation.

  • ✓

    Incident response costs

    Why this is correct

    Incident response costs count as a secondary loss in FAIR's Loss Magnitude, arising after the primary loss event rather than from the threat event itself. This satisfies the stem's requirement by capturing response and remediation expenditure triggered by the incident, distinguishing it from primary loss factors such as productivity or response-related replacement costs.

  • ✓

    Recovery costs

    Why this is correct

    Recovery costs form part of secondary loss in FAIR, capturing the expense of restoring assets and operations after an event. This satisfies the stem's requirement for a Loss Magnitude component, since Loss Magnitude comprises both primary loss (the event's direct impact) and secondary loss, which includes recovery, response and replacement costs.

  • ✗

    Threat event frequency

    Why it's wrong here

    Threat event frequency sits within Loss Event Frequency, estimating how often threat agents act against assets. It is tempting because frequency appears measurable and loss-related, and would be correct when quantifying how often loss events occur rather than their magnitude.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.