CRISC IT Risk Assessment Techniques 2 — Questions and Answers
Question 1: The Delphi technique is MOST useful in risk assessment for which purpose?
- Reaching consensus among experts without groupthink bias (Correct answer)
- Automating the collection of risk metrics
- Quantifying the financial impact of risks
- Documenting the results of a penetration test
Correct answer: Reaching consensus among experts without groupthink bias
The Delphi technique uses structured, anonymous rounds of expert input to build consensus on risk assessments while minimizing groupthink.
Question 2: When assessing the impact of a risk, a CRISC practitioner should consider which dimension FIRST?
- Business impact rather than technical impact (Correct answer)
- The cost of the exploited vulnerability patch
- The number of systems affected by the risk
- The technical severity score from a scanning tool
Correct answer: Business impact rather than technical impact
Business impact (financial, reputational, operational) should be the primary consideration because it directly connects risk to organizational objectives.
Question 3: Which risk assessment output BEST supports prioritization of risk remediation efforts?
- A risk heat map showing likelihood vs. impact (Correct answer)
- A list of all identified vulnerabilities by CVE score
- A count of total risks per business unit
- An inventory of all IT assets and their owners
Correct answer: A risk heat map showing likelihood vs. impact
A risk heat map visually plots risks by likelihood and impact, making it easy to prioritize the highest-priority risks for remediation.
Question 4: In IT risk assessment, exposure factor (EF) represents:
- The percentage of an asset's value lost if a threat event occurs (Correct answer)
- The annual frequency at which a threat is expected to occur
- The total value of all assets at risk
- The cost of implementing a compensating control
Correct answer: The percentage of an asset's value lost if a threat event occurs
The exposure factor is the percentage of an asset's value that would be lost in a single threat event, used to calculate Single Loss Expectancy.
Question 5: A risk assessment that evaluates risks AFTER controls are applied is measuring:
- Residual risk (Correct answer)
- Inherent risk
- Control risk
- Detection risk
Correct answer: Residual risk
Residual risk is the level of risk remaining after controls have been implemented, representing the organization's actual remaining exposure.
Question 6: Which factor should be considered when determining the frequency component of a risk assessment?
- Historical incident data and threat intelligence (Correct answer)
- The organization's annual IT budget
- The number of IT staff available for response
- The vendor's patch release schedule
Correct answer: Historical incident data and threat intelligence
Frequency (likelihood) is best estimated using historical incident records and current threat intelligence relevant to the organization's environment.
The Delphi technique is MOST useful in risk assessment for which purpose?