Courseiva
hardMultiple Select

CRISC Practice Question: Which THREE of the following are typical…

Which THREE of the following are typical components of a risk scenario?

⚠ Common exam trap

Many exam-takers confuse the components of a risk scenario (threat source, vulnerability, impact) with the elements of risk analysis (probability, control effectiveness), leading them to incorrectly select Probability or Control as scenario components.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Impact

A risk scenario typically combines a threat source, a vulnerability, and an impact, so options B, D, and A are correct. B (Threat source) is right because a risk scenario must identify who or what could cause harm, such as an attacker, malware, or environmental event. D (Vulnerability) is right because the scenario must describe the weakness or exposure that the threat source could exploit, such as an unpatched service or misconfiguration. A (Impact) is right because the scenario must state the potential consequence or harm to the asset, such as data loss, downtime, or financial damage. C (Probability) is not a core component of the scenario itself; it is an assessment or estimate applied to the scenario, and E (Control) is a mitigating measure, not a defining element of the risk scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Impact

    Why this is correct

    Impact quantifies the consequence if the risk event occurs, expressed in financial, operational or regulatory terms. It is a core component of a risk scenario, alongside the threat source and the event itself, enabling consistent comparison and prioritisation.

  • ✓

    Threat source

    Why this is correct

    The threat source identifies who or what could exploit a vulnerability, such as an external attacker, insider or natural event. Naming it anchors the scenario to a realistic cause, which is essential for assessing likelihood and selecting proportionate risk responses.

  • ✗

    Probability

    Why it's wrong here

    Probability is a risk factor, not a scenario component; a scenario pairs a threat with an asset and a consequence. It is tempting because likelihood estimates are central to risk analysis, and probability would be correct when quantifying how often a given scenario is expected to occur.

  • ✓

    Vulnerability

    Why this is correct

    A vulnerability is a weakness in an asset or control that a threat can exploit, so it forms one leg of the risk scenario triad alongside threat and impact. Naming it lets analysts assess how likely an adverse event is and which existing safeguards need strengthening.

  • ✗

    Control

    Why it's wrong here

    A control is a response that modifies risk, not a component used to describe it. Risk scenarios are built from asset, threat, vulnerability, event and consequence; controls appear only after assessment, when selecting treatment. It tempts because controls are central to risk management and would be the correct focus when evaluating whether existing mitigations adequately reduce an identified risk.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.