CRISC domain - 22% of the exam

Risk Assessment

Risk Assessment is 22% of the Certified in Risk and Information Systems Control (CRISC) (CRISC) exam. These are the objectives it covers, each with practice questions and worked explanations.

Objectives in this domain

Sample question from this domain

Free sampleRisk Assessmentmedium

A risk practitioner is documenting an IT risk scenario for a customer-facing payment service. Which combination of components makes the scenario most useful for analysis and response?

  • AA list of every control currently operating on the payment platform and its last test date
  • BA detailed network diagram of the payment platform and the data flows between each hosted component
  • CA summary of past audit findings raised against the payment service over the previous three years
  • DA threat actor, the event, the affected asset and the resulting business loss consequence Correct
A usable IT risk scenario binds a threat actor, an event, an affected asset and a loss consequence together. Risk scenarios become analysable only when they connect who or what triggers the event, the asset affected and the business consequence, because likelihood and impact estimates depend on all four elements being present.

Why A is wrong: Cataloguing existing controls describes the current state but omits the threat, event and consequence, so it cannot frame what could go wrong or how badly.

Why B is wrong: An architecture diagram supports analysis but is an input, not a scenario, because on its own it states no event, no actor and no loss outcome.

Why C is wrong: Prior findings are useful history but describe known weaknesses, not a forward-looking event with an actor and a quantifiable loss consequence.

Why D is correct: A complete scenario links actor, event, asset and consequence, giving analysts enough context to estimate likelihood and impact and to design a proportionate response.

Other domains in this exam

See also the CRISC cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.