nerdexam
Isaca

CRISC · Question #30

An IT risk threat analysis is BEST used to establish

The correct answer is A. risk scenarios. An IT risk threat analysis is best used to establish detailed risk scenarios, as it systematically identifies potential threats, vulnerabilities, and their potential impacts on IT assets. This analysis forms the basis for constructing specific and actionable risk scenarios.

Submitted by yasin.bd· Apr 18, 2026IT Risk Assessment

Question

An IT risk threat analysis is BEST used to establish

Options

  • Arisk scenarios
  • Brisk maps
  • Crisk appetite
  • Drisk ownership.

How the community answered

(28 responses)
  • A
    89% (25)
  • B
    7% (2)
  • C
    4% (1)

Why each option

An IT risk threat analysis is best used to establish detailed risk scenarios, as it systematically identifies potential threats, vulnerabilities, and their potential impacts on IT assets. This analysis forms the basis for constructing specific and actionable risk scenarios.

Arisk scenariosCorrect

An IT risk threat analysis systematically identifies potential threats (e.g., cyberattacks, natural disasters), vulnerabilities (e.g., unpatched systems, weak configurations), and the assets they could impact. By combining these elements, the analysis helps to formulate specific "what if" situations or risk scenarios that describe how a threat could exploit a vulnerability to cause harm, which are then assessed in the risk management process.

Brisk maps

Risk maps (or heat maps) are visual representations of risks based on their likelihood and impact, which are developed *after* risk scenarios have been identified and assessed.

Crisk appetite

Risk appetite defines the level of risk an organization is willing to accept to achieve its objectives, which is a strategic decision made at a higher level, not directly established by a technical threat analysis.

Drisk ownership.

Risk ownership assigns accountability for managing specific risks, a governance decision made after risks have been identified and analyzed, not by the threat analysis itself.

Concept tested: Purpose of threat analysis

Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-30r1.pdf

Topics

#IT risk assessment#Threat analysis#Risk scenarios#Risk identification

Community Discussion

No community discussion yet for this question.

Full CRISC Practice