CRISC IT Risk Assessment Techniques 1 — Questions and Answers
Question 1: Which risk assessment technique uses historical data and probability distributions to simulate thousands of possible risk scenarios?
- Monte Carlo simulation (Correct answer)
- Delphi technique
- Bowtie analysis
- SWOT analysis
Correct answer: Monte Carlo simulation
Monte Carlo simulation runs large numbers of probabilistic simulations based on historical data to estimate the range of possible risk outcomes.
Question 2: In a qualitative risk assessment, risks are PRIMARILY evaluated using:
- Descriptive scales such as High, Medium, and Low (Correct answer)
- Dollar value of potential losses
- Statistical probability distributions
- Return on security investment calculations
Correct answer: Descriptive scales such as High, Medium, and Low
Qualitative risk assessment uses descriptive scales rather than numerical values to rate likelihood and impact of risks.
Question 3: The PRIMARY advantage of quantitative risk assessment over qualitative is:
- It provides dollar-value estimates that support financial decision-making (Correct answer)
- It is faster to perform and requires less data
- It eliminates subjectivity completely from the process
- It is easier to communicate to non-technical stakeholders
Correct answer: It provides dollar-value estimates that support financial decision-making
Quantitative risk assessment produces financial estimates (e.g., ALE) that directly support cost-benefit analysis and budget decisions.
Question 4: Which formula correctly represents Annualized Loss Expectancy (ALE)?
- ALE = SLE × ARO (Correct answer)
- ALE = AV × EF + ARO
- ALE = ARO / SLE
- ALE = SLE + ARO
Correct answer: ALE = SLE × ARO
ALE is calculated by multiplying Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO) to estimate annual risk cost.
Question 5: A threat-vulnerability pairing is used in risk assessment to determine:
- The likelihood that a specific threat will exploit a given vulnerability (Correct answer)
- The total cost of implementing a security control
- The organizational risk appetite for IT risks
- The residual risk after controls are applied
Correct answer: The likelihood that a specific threat will exploit a given vulnerability
Pairing threats with vulnerabilities helps assessors determine the probability that a specific threat source will successfully exploit an existing weakness.
Question 6: Which risk assessment approach is MOST appropriate when limited historical data is available?
- Qualitative assessment using expert judgment (Correct answer)
- Quantitative assessment using actuarial data
- Monte Carlo simulation
- Regression analysis
Correct answer: Qualitative assessment using expert judgment
Qualitative assessment using expert judgment is most practical when historical data is insufficient for statistical or quantitative analysis.
Which risk assessment technique uses historical data and probability distributions to simulate thousands of possible risk scenarios?