Courseiva
mediumMultiple Select

CRISC Practice Question: Which TWO of the following are primary factors…

Which TWO of the following are primary factors that determine how often a risk assessment should be performed?

⚠ Common exam trap

Many exam-takers confuse operational constraints (budget, staff count) or reactive metrics (past incidents) with the proactive, risk-driven factors that ISACA emphasizes for determining assessment frequency, leading them to select budget or incident count instead of change rate and inherent risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rate of change in the IT environment

Option B is correct because the rate of change in the IT environment directly drives how quickly risk exposure can shift — new systems, cloud migrations, software updates, and architecture changes can invalidate a prior assessment, so faster change demands more frequent reassessment. Option D is correct because the inherent risk level of critical assets determines the potential impact and likelihood of loss; high-inherent-risk assets (e.g., those processing sensitive data or supporting critical services) warrant more frequent risk assessments than low-risk assets. Option A is not a primary factor — budget is a constraint on how assessments are executed, not a driver of the required frequency. Option C is not a primary factor — headcount does not by itself change the risk landscape or the need for reassessment. Option E is not a primary factor — past incidents may inform risk ratings, but the frequency of assessment is driven by change and inherent risk, not by a historical incident count.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Available risk assessment budget

    Why it's wrong here

    Budget constrains how much assessment work is affordable, but frequency is driven by risk appetite, threat landscape and change velocity. It tempts because resourcing does limit scope in practise; budget would be the deciding factor when planning assessment coverage, not the interval itself.

  • ✓

    Rate of change in the IT environment

    Why this is correct

    A rapidly changing IT environment invalidates prior assessments quickly, so the interval must shorten to keep risk pictures current. This directly determines assessment frequency, unlike static factors such as organisational size or historical loss data.

  • ✗

    Number of IT employees

    Why it's wrong here

    Headcount reflects organisational capacity, not the rate at which risk exposure changes. It tempts because staffing does constrain how much assessment work can be delivered; IT employee numbers would matter when sizing the assessment team, not when setting reassessment frequency.

  • ✓

    Inherent risk level of critical assets

    Why this is correct

    Assets carrying higher inherent risk warrant more frequent assessment, because their exposure and potential impact change faster and demand closer monitoring. This factor directly drives assessment cadence, alongside regulatory requirements and the rate of change in the environment.

  • ✗

    Number of past security incidents

    Why it's wrong here

    Past incident counts are historical and lagging; frequency should follow current risk appetite, threat landscape and rate of change. It tempts because incidents do prompt reassessment after the fact; incident volume would justify an ad hoc review, not the standing assessment cadence.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.