CRISC - Risk Assessment (22% of the exam) - Section 2.6

Perform risk analysis using qualitative and quantitative methodologies to estimate likelihood and impact.

Perform risk analysis using both qualitative methods - such as likelihood and impact matrices - and quantitative methods including annualised loss expectancy calculations. Weigh the precision and data requirements of each approach to choose the methodology appropriate to the available information.

Qualitative analysisQuantitative analysisAnnualised loss expectancyLikelihood and impact

Practice question for this objective

Free sampleRisk Assessmenthard

A risk practitioner has calculated the single loss expectancy for a customer database breach as 800,000 and judges that such a breach occurs roughly once every four years. Which annualised loss expectancy should be reported to support the comparison of this risk against the cost of a proposed control?

  • A3,200,000, because the single loss expectancy is multiplied by the four-year exposure window to show full lifetime loss.
  • B200,000, because the single loss expectancy is multiplied by an annualised rate of occurrence of 0.25 events per year. Correct
  • C800,000, because the single loss expectancy is itself the annualised figure once a credible breach scenario has been defined.
  • D400,000, because the single loss expectancy is halved to reflect the average position across the four-year recurrence cycle.
Annualised loss expectancy equals single loss expectancy multiplied by the annualised rate of occurrence of the event. Annualised loss expectancy is single loss expectancy times annualised rate of occurrence. An event recurring once every four years has an annualised rate of occurrence of 0.25, so the correct figure is 800,000 multiplied by 0.25, giving 200,000 per year for comparison against annual control cost.

Why A is wrong: This multiplies single loss expectancy by the number of years rather than the annual rate of occurrence, inflating the figure and misrepresenting the metric the formula produces.

Why B is correct: Annualised loss expectancy equals single loss expectancy times annualised rate of occurrence, and one event every four years gives a rate of 0.25, so 800,000 times 0.25 is 200,000.

Why C is wrong: This treats single loss expectancy as already annualised, which is tempting but ignores that frequency below once per year must scale the value down.

Why D is wrong: Halving the loss has no basis in the annualised loss expectancy formula and confuses an averaging heuristic with the rate of occurrence multiplier.

See more CRISC practice questions, answers explained.

Exam traps in Risk Assessment

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • A Delphi technique, in which anonymous experts iterate their judgements until the group converges on a single agreed rating for each information risk.

    Why it is wrong: The Delphi technique structures expert consensus, which is useful when data is scarce, but it produces agreed ratings rather than a defined factor taxonomy that decomposes risk into frequency and magnitude, so it does not meet the stated aim.

  • 500,000, calculated as the asset value of 2,000,000 multiplied by the exposure factor of 0.25 for the event.

    Why it is wrong: This is the single loss expectancy for one occurrence and is tempting, but it ignores the once-in-five-years frequency that the annualised figure must include.

  • Annualised loss expectancy understates frequent risks because recurring small losses accumulate faster than the annual figure suggests over a multi-year horizon.

    Why it is wrong: This sounds plausible, but the annualised figure already captures the yearly total of frequent small losses, so the real gap concerns the severity distribution of the rare event.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.