CISA Risk appetite Practice Question
An organization's IT governance committee is reviewing a proposal to use a public cloud provider that does not meet the organization's data encryption standards. The board has set a low risk appetite for data privacy. What is the BEST action?
⚠ Common exam trap
CISA often tests the misconception that additional monitoring or waivers can compensate for a control gap when the risk appetite is low, but the correct answer is to reject non-compliant proposals outright.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reject the proposal until encryption requirements are met
The board has set a low risk appetite for data privacy, meaning the organization is willing to accept only minimal risk in this area. A cloud provider that does not meet the organization's data encryption standards introduces a risk that exceeds this appetite. Therefore, the proposal must be rejected until the provider can comply with the encryption requirements. This aligns with governance principles where risk decisions must be made in accordance with the organization's risk appetite.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the proposal with additional monitoring
Why it's wrong here
Additional monitoring does not reduce the encryption gap itself, so residual data-privacy risk still exceeds the board's low appetite. Monitoring suits higher-appetite environments where exposure is tolerated and watched; here the governance committee must align with the board's mandate, meaning the proposal should be declined or the provider required to meet the standard.
- ✗
Delegate the decision to the security team
Why it's wrong here
Delegating to the security team abdicates the governance committee's accountability for aligning decisions with board risk appetite. Security teams advise on controls, but acceptance of a non-compliant provider is a governance decision the committee must own; with low appetite for data privacy, the proposal should be rejected or remediated.
- ✗
Accept the proposal but require the provider to sign a waiver
Why it's wrong here
A waiver signed by the provider transfers no risk and cannot override the board's low risk appetite for data privacy. Governance requires aligning decisions with stated risk tolerance, so accepting non-compliant encryption contradicts the board's mandate; the correct action rejects or remediates the proposal rather than documenting the gap.
- ✓
Reject the proposal until encryption requirements are met
Why this is correct
Rejecting the proposal directly enforces the board's low risk appetite for data privacy, since the provider's encryption controls fall short of the organisation's mandated standards. Accepting residual privacy risk would exceed that appetite. Governance committees must align procurement decisions with stated risk tolerance rather than accept unmitigated control gaps.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.