CISM Information Security Risk Management Practice Question
Which THREE of the following are valid risk treatment options according to ISO 31000? (Select exactly three.)
⚠ Common exam trap
ISACA often tests the distinction between 'risk elimination' and 'risk avoidance' to trap candidates who confuse the two, as elimination implies complete removal of the risk source, which is rarely achievable in information security, while avoidance means not engaging in the risky activity at all.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk transfer (sharing)
According to ISO 31000, risk treatment options include avoiding the risk (Option C), which means deciding not to start or continue the activity that gives rise to the risk, thereby removing the exposure entirely. Option B, risk transfer (sharing), is also valid because it involves sharing the risk with another party, such as through insurance or contractual arrangements, while retaining some residual risk. Option D, risk mitigation (reduction), is correct because ISO 31000 recognizes modifying the likelihood and/or consequence of the risk to reduce it to an acceptable level. Option A, risk elimination, is not one of the standard ISO 31000 treatment categories; while avoidance can eliminate exposure, 'elimination' is not the named treatment option. Option E, risk deferral, is not a recognized ISO 31000 risk treatment option, as postponing a risk does not by itself treat it and ISO 31000 does not list deferral among its treatment choices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk elimination
Why it's wrong here
ISO 31000 lists avoid, reduce, transfer, and accept as risk treatment options; elimination is not one of them, since avoiding an activity removes the risk source rather than treating an identified risk. It is tempting because elimination sounds like the strongest response, and it would fit a scenario asking how to remove a risk entirely by discontinuing the activity.
- ✓
Risk transfer (sharing)
Why this is correct
Risk transfer (sharing) is an ISO 31000 treatment that shifts the financial impact of a threat to a third party, such as through insurance or outsourcing contracts. The organisation retains accountability, so it satisfies the stem's requirement for a valid treatment option.
- ✓
Risk avoidance
Why this is correct
Risk avoidance eliminates the activity or exposure that generates the risk entirely, removing the threat rather than reducing its likelihood or impact. ISO 31000 lists avoidance as a distinct treatment, satisfying the stem's requirement for a valid option.
- ✓
Risk mitigation (reduction)
Why this is correct
Risk mitigation (reduction) lowers either the likelihood or the consequence of a risk through controls, without transferring or eliminating it. ISO 31000 recognises this as a core treatment, satisfying the stem's requirement for a valid option.
- ✗
Risk deferral
Why it's wrong here
ISO 31000 treatment options are avoid, reduce, transfer, and accept; deferral merely postpones action and leaves the risk untreated, so it is not a recognised option. It is tempting because scheduling treatment later sounds like a decision, but it would only be relevant when documenting a temporary management response, not a treatment category.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.