Selecting the Right Risk Treatment Strategy for CISM Scenarios
A financial institution is implementing a new online banking platform. The risk assessment identified that the authentication module has a high likelihood of exploitation due to weak password policies. The risk owner has decided to implement multi-factor authentication (MFA) to reduce the risk. This is an example of which risk response strategy?
⚠ Common exam trap
Many exam-takers confuse 'risk mitigation' with 'risk avoidance' because both involve implementing controls, but avoidance means eliminating the activity or technology entirely, whereas mitigation reduces but does not eliminate the risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk mitigation
Implementing multi-factor authentication (MFA) reduces the likelihood or impact of a security risk by adding additional authentication factors (e.g., something you know, something you have, something you are) beyond a weak password. This directly aligns with risk mitigation, which seeks to decrease the residual risk to an acceptable level through controls. The decision does not eliminate the risk entirely (avoidance), accept it without action, or transfer it to a third party.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk avoidance
Why it's wrong here
Risk avoidance eliminates the activity or exposure entirely, such as withdrawing the online banking service; adding MFA retains the platform while lowering the likelihood of exploitation. It is tempting because avoidance sounds decisive, and it would be correct if the institution abandoned the vulnerable authentication module rather than strengthening it.
- ✓
Risk mitigation
Why this is correct
Implementing MFA reduces the likelihood of exploitation by adding a second authentication factor, lowering the inherent risk while retaining the activity. Mitigation treats risk through controls rather than transferring, avoiding or accepting it, matching the risk owner's decision.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance involves no new controls and formally tolerates the exposure, often with monitoring; deploying MFA actively reduces likelihood, which is mitigation. It is tempting because residual risk is always accepted after treatment, and it would be correct if the owner documented the weak-password risk and proceeded without remediation.
- ✗
Risk transfer
Why it's wrong here
Risk transfer shifts the financial impact to a third party, typically via insurance or contractual indemnity; implementing MFA changes the control environment itself, leaving the residual risk with the institution. It is tempting because cyber-insurance is common in banking, and it would be correct if an insurer were to absorb losses from authentication breaches.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on CISM
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During a risk assessment, a CISM identifies that the organization's data backup process has a single point of failure. The backup server is located in the same data center as the primary server. Which risk response is most appropriate?
easy- ✓ A.Mitigate by moving the backup server to a geographically separate location.
- B.Transfer the risk by purchasing business interruption insurance.
- C.Avoid the risk by discontinuing the backup process.
- D.Accept the risk because the cost of mitigation is high.
Why A: Moving the backup server to a geographically separate location directly eliminates the single point of failure by ensuring that a localized disaster (e.g., fire, flood, power outage) at the primary data center does not simultaneously destroy both the primary and backup data. This is a classic risk mitigation strategy that reduces the likelihood and impact of data loss, aligning with the principle of geographic redundancy for disaster recovery.
Variation 2. During a risk assessment, a company discovers that its data backup process is incomplete: backups are performed daily but stored onsite without encryption. The risk owner proposes to accept this risk due to low likelihood of a physical breach. Which of the following is the BEST reason to challenge this acceptance?
medium- ✓ A.The impact of losing both primary and backup data is unacceptably high
- B.The risk owner does not have authority to accept risks
- C.Encryption is not required as the facility is secure
- D.The cost of implementing encrypted offsite backups is minimal
Why A: The core principle of risk acceptance requires that the residual risk be within the organization's risk appetite. In this scenario, the backup data is stored onsite without encryption, meaning a single physical breach (e.g., fire, theft, or natural disaster) could destroy both primary and backup data simultaneously. The impact of losing all data—potentially leading to business failure—is unacceptably high, outweighing the low likelihood of a physical breach. The risk owner's acceptance is invalid because the risk exceeds the organization's risk tolerance, as per CISM's risk management framework.
Variation 3. A company is assessing the risk of a critical system outage. The system has a maximum tolerable downtime (MTD) of 2 hours, but the current recovery time objective (RTO) is 4 hours. What is the most appropriate risk treatment?
medium- ✓ A.Mitigate by reducing the RTO to 1 hour through process automation
- B.Transfer the risk by purchasing business interruption insurance
- C.Accept the risk because the RTO is shorter than the MTD
- D.Avoid the risk by replacing the system with a more reliable one
Why A: The current RTO of 4 hours exceeds the MTD of 2 hours, meaning the system cannot be restored within the maximum tolerable downtime, resulting in unacceptable business impact. Reducing the RTO to 1 hour through process automation brings recovery time well within the MTD, effectively mitigating the risk to an acceptable level. This aligns with the risk management principle of applying controls to close the gap between RTO and MTD.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.