Which Process Determines Threat Relevance for Risk Scenarios?

Which process is MOST effective to determine relevance of threats for risk scenarios?

  1. Penetration testing Source Reference Answer
  2. Vulnerability assessment
  3. Root cause analysis
  4. Business impact analysis (BIA)

Community Votes

A
50%
B
50%

50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your ability to distinguish between threat identification and risk validation, where the common trap is selecting penetration testing due to its active nature rather than recognizing vulnerability assessment's broader relevance-mapping capability.

Determining threat relevance requires systematically mapping potential threats to existing system weaknesses to filter out theoretical risks. The community consensus confirms that vulnerability assessment is the most effective method for this purpose, enabling precise alignment of threats with actual business scenarios.

Candidates frequently choose penetration testing because it demonstrates actual exploitation, but it is designed to validate security controls for specific targets rather than comprehensively determine which threats are relevant across multiple risk scenarios.

Community Discussion (3 comments)

d9iceguy 👍 1 Selected: B
A vulnerability assessment is the most effective process to determine the relevance of threats for specific risk scenarios because it: Identifies weaknesses or exposures in systems, applications, or processes. Helps correlate which threats are actually applicable based on known vulnerabilities. Enables risk practitioners to prioritize risk scenarios based on realistic threat vectors. By understanding the organization’s vulnerabilities, practitioners can determine which threats are relevant and likely to be exploited, making the risk scenario more accurate and actionable.
kaykaymuon 👍 1 Selected: A
I think A is the most correct answer, reason being that threats exploits vulnerabilities so unless a threat exploits a vulnerability a risk event would not occur.
Rozitas 👍 1
Vulnerability Assessment is the answer. A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Vulnerability assessment systematically identifies and catalogs weaknesses across IT infrastructure, applications, and processes. By cross-referencing these documented weaknesses with known threat actors and methodologies, risk professionals can accurately filter and prioritize which threats are genuinely relevant to specific organizational scenarios. This evidence-based approach aligns with CRISC principles that emphasize mapping threats to actual exposure points before calculating risk.

Why the Other Options Are Wrong

Penetration testing actively attempts to exploit identified vulnerabilities to prove security gaps, making it a control validation tool rather than a systematic relevance-determination process. Root cause analysis is a reactive investigation technique performed after an incident has occurred, rendering it unsuitable for proactive threat mapping. Business impact analysis quantifies the financial and operational consequences of service disruptions, focusing exclusively on impact severity rather than threat applicability or likelihood.

Community Comment Notes

Multiple highly rated comments correctly identify vulnerability assessment as the right answer, emphasizing its role in correlating theoretical threats with real-world system exposures. One top-voted explanation highlights that vulnerability assessments enable practitioners to prioritize risk scenarios based on realistic threat vectors instead of abstract possibilities. Another user initially selected penetration testing but provided reasoning that actually describes vulnerability mapping, illustrating how easily test-takers confuse active exploitation with systematic threat relevance evaluation.

Official Reference

Exam Strategy

Always differentiate between proactive identification tools and reactive or validation techniques when analyzing risk-related questions. If a question emphasizes determining relevance, applicability, or mapping threats to scenarios, prioritize assessment and analysis frameworks over hands-on testing or post-incident reviews.

Related Analysis

Practice All CRISC Questions

Access 332 questions with complete answers and detailed explanations.

View Full CRISC Practice Test →

← Back to CRISC Study Guide