20+ practice questions focused on Risk Response and Mitigation — one of the most tested topics on the Certified in Risk and Information Systems Control CRISC exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Risk Response and Mitigation PracticeWhich TWO of the following are effective risk mitigation strategies for reducing the likelihood of a ransomware attack?
Explanation: Deploying network segmentation (D) reduces the likelihood of a ransomware attack by limiting lateral movement. If an endpoint is compromised, segmentation using VLANs or firewall rules (e.g., 802.1Q, ACLs) prevents the ransomware from spreading to critical systems, thereby reducing the attack surface and the probability of widespread encryption. User awareness training (E) directly reduces likelihood by teaching users to recognize phishing emails and malicious attachments, which are the primary initial vectors for ransomware delivery.
Refer to the exhibit. A risk practitioner is reviewing the access control list for a critical server. The ACL is applied inbound on the interface connecting to the internet. Which of the following is the MOST significant risk?
Explanation: Permitting all HTTPS (TCP/443) and DNS (UDP/53) traffic from any source on the internet to the critical server unnecessarily exposes the server to potential exploitation of vulnerabilities in the web server software (e.g., Apache, Nginx) and DNS resolver services. This broad permit statement increases the attack surface significantly, as HTTPS and DNS are common vectors for attacks such as SQL injection, cross-site scripting, and DNS amplification or tunneling. The risk is heightened because the ACL is applied inbound on the internet-facing interface, meaning all external traffic matching these protocols is allowed without restriction, bypassing any stateful inspection or application-layer filtering.
A risk assessment for a financial trading platform has identified a high-risk vulnerability in the order matching engine. The risk owner has recommended implementing compensating controls rather than fixing the underlying code. Which TWO of the following are valid compensating controls? (Choose two.)
Explanation: Option D is correct because requiring manual approval for orders above a threshold is a compensating control: it does not fix the vulnerable matching engine code but reduces the likelihood and impact of exploitation by inserting a human review step before high-value transactions are processed. Option E is correct because rate limiting on order submissions is also a compensating control: it constrains how quickly an attacker (or malformed automated traffic) can exercise the vulnerability, limiting abuse without modifying the underlying code. Option A is not a compensating control but a remediation/root-cause fix, since rewriting the engine in a memory-safe language eliminates the vulnerability itself. Option B is not appropriate here because a WAF protects HTTP/application-layer web traffic and cannot meaningfully inspect or block malicious payloads directed at an internal order matching engine's native protocol. Option C is not a compensating control because detailed logging is a detective control that records activity for auditing and forensics; it does not prevent, block, or reduce the impact of exploitation.
Match each risk management process step to its activity.
Explanation: The risk management process steps are distinct: Risk Identification finds risks, Risk Assessment evaluates them, and Risk Response addresses them. Common confusions involve swapping these definitions.
An organization is considering outsourcing its IT support to a third-party provider. The risk manager has identified that the provider's data handling practices may not comply with regulatory requirements. Which of the following is the BEST risk response strategy?
Explanation: The risk manager has identified that the provider's data handling practices may not comply with regulatory requirements, which represents a high-severity compliance risk that cannot be effectively mitigated through monitoring alone. Avoiding the risk by keeping IT support in-house eliminates the exposure entirely, making it the best response when the risk level exceeds the organization's risk appetite and cannot be reduced to an acceptable level through other strategies.
+15 more Risk Response and Mitigation questions available
Practice all Risk Response and Mitigation questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Risk Response and Mitigation. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Risk Response and Mitigation questions on the CRISC frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Risk Response and Mitigation is tested as part of the Certified in Risk and Information Systems Control CRISC blueprint. Practicing with targeted Risk Response and Mitigation questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CRISC practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Risk Response and Mitigation is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Risk Response and Mitigation practice session with instant scoring and detailed explanations.
Start Risk Response and Mitigation Practice →