CRISC Risk Response and Mitigation Practice Question
A company faces a risk of data loss due to untrained staff. They implement mandatory training and quarterly phishing simulations. This is:
⚠ Common exam trap
Many exam-takers confuse 'risk mitigation' with 'risk avoidance' because they think training eliminates the risk entirely, but mitigation only reduces it, while avoidance would require stopping the use of email or data processing altogether.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk Mitigation
Mandatory training and quarterly phishing simulations are proactive controls that reduce the likelihood and impact of data loss from human error. This directly aligns with risk mitigation, which seeks to lower residual risk to an acceptable level without eliminating the activity or transferring the financial burden. The controls target the root cause (untrained staff) by improving security awareness and testing behavioral response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk Avoidance
Why it's wrong here
Avoidance eliminates the activity generating the risk entirely; training and simulations retain the staff and the exposure, merely reducing likelihood. It is tempting because removing the cause feels decisive, yet avoidance would mean halting the at-risk processing itself, which the company has not done.
- ✗
Risk Acceptance
Why it's wrong here
Acceptance means acknowledging the risk and taking no mitigating action; mandatory training and quarterly simulations are active controls that lower likelihood. It is tempting because residual risk always remains, but acceptance describes the absence of treatment, not the implementation of new safeguards.
- ✓
Risk Mitigation
Why this is correct
Training and phishing simulations reduce the likelihood of staff falling for attacks, lowering the risk's expected impact rather than avoiding, transferring or accepting it. The controls target the human cause directly, so the treatment is risk mitigation.
- ✗
Risk Transfer
Why it's wrong here
Transfer shifts financial consequence to a third party through insurance or contracts; training and phishing simulations change staff behaviour instead, leaving the loss on the company's books. It is tempting because both are deliberate responses, but transfer requires an external party absorbing the impact, which is absent here.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.