Risk-based testing prioritizes test effort based on the likelihood and impact of failures. High-risk areas (critical functionality, complex logic, frequently changed code) deserve priority because defects there cause the most harm. While coverage and fault counts matter, they're secondary to targeting areas where failures would be most damaging.