What Must Risk Scenarios Include?
When a risk practitioner is developing a set of risk scenarios, the scenarios MUST include information about:
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests foundational knowledge of risk scenario architecture, commonly trapping candidates who confuse post-event impact metrics with prerequisite scenario inputs.
Effective risk scenario development hinges on identifying the entities that could exploit system vulnerabilities. The CRISC community unanimously agrees that relevant threat agents are a mandatory component for building accurate and actionable risk models.
Some test-takers incorrectly choose threat impact analysis results, mistakenly believing that quantifying potential damage takes precedence over defining the actual sources of risk during scenario construction.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Risk scenarios must explicitly define the relevant threat agents because they represent the actors or events capable of exploiting vulnerabilities. Without identifying these agents, practitioners cannot logically map attack paths, assess likelihood, or design appropriate controls. ISACA’s CRISC Review Manual emphasizes that threat identification is the foundational step before evaluating impacts or control effectiveness.Why the Other Options Are Wrong
Control efficiency measures how well existing safeguards mitigate risks, which is evaluated after scenarios are established. Threat impact analysis results and severity of occurrences are outcome metrics derived from running the scenarios, not prerequisites for drafting them. Focusing on these downstream elements skips the critical initial phase of defining who or what poses the threat.Community Comment Notes
Multiple high-rated comments reinforce that threat agents encompass hackers, natural disasters, and insider threats, making them indispensable for realistic modeling. Contributors note that understanding the nature and capabilities of these entities directly enables actionable risk prioritization. The unanimous vote distribution confirms this is a straightforward, definition-based CRISC concept.Official Reference
Exam Strategy
Always distinguish between scenario inputs (threats, vulnerabilities, assets) and scenario outputs (impact, likelihood, residual risk). When unsure, ask yourself whether the option helps you build the scenario or measures its result.
Related Analysis
Practice All CRISC Questions
Access 332 questions with complete answers and detailed explanations.
View Full CRISC Practice Test →