hardMultiple Select
CRISC Practice Question: Which THREE of the following are typical…
Which THREE of the following are typical components of a risk scenario?
⚠ Common exam trap
Many exam-takers confuse the components of a risk scenario (threat source, vulnerability, impact) with the elements of risk analysis (probability, control effectiveness), leading them to incorrectly select Probability or Control as scenario components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Impact
A risk scenario typically combines a threat source, a vulnerability, and an impact, so options B, D, and A are correct. B (Threat source) is right because a risk scenario must identify who or what could cause harm, such as an attacker, malware, or environmental event. D (Vulnerability) is right because the scenario must describe the weakness or exposure that the threat source could exploit, such as an unpatched service or misconfiguration. A (Impact) is right because the scenario must state the potential consequence or harm to the asset, such as data loss, downtime, or financial damage. C (Probability) is not a core component of the scenario itself; it is an assessment or estimate applied to the scenario, and E (Control) is a mitigating measure, not a defining element of the risk scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Impact
Why this is correct
Impact quantifies the consequence if the risk event occurs, expressed in financial, operational or regulatory terms. It is a core component of a risk scenario, alongside the threat source and the event itself, enabling consistent comparison and prioritisation.
- ✓
Threat source
Why this is correct
The threat source identifies who or what could exploit a vulnerability, such as an external attacker, insider or natural event. Naming it anchors the scenario to a realistic cause, which is essential for assessing likelihood and selecting proportionate risk responses.
- ✗
Probability
Why it's wrong here
Probability is a risk factor, not a scenario component; a scenario pairs a threat with an asset and a consequence. It is tempting because likelihood estimates are central to risk analysis, and probability would be correct when quantifying how often a given scenario is expected to occur.
- ✓
Vulnerability
Why this is correct
A vulnerability is a weakness in an asset or control that a threat can exploit, so it forms one leg of the risk scenario triad alongside threat and impact. Naming it lets analysts assess how likely an adverse event is and which existing safeguards need strengthening.
- ✗
Control
Why it's wrong here
A control is a response that modifies risk, not a component used to describe it. Risk scenarios are built from asset, threat, vulnerability, event and consequence; controls appear only after assessment, when selecting treatment. It tempts because controls are central to risk management and would be the correct focus when evaluating whether existing mitigations adequately reduce an identified risk.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.