CRISC IT Risk Assessment Practice Question
A company is considering risk transfer for a new IT project. Which TWO options represent valid risk transfer mechanisms? (Select TWO)
⚠ Common exam trap
CRISC often tests the confusion between risk response strategies — candidates frequently misclassify mitigation (controls) or avoidance (discontinuing) as transfer, when transfer specifically requires a third party to assume the financial impact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Purchasing cyber insurance
Option B (Purchasing cyber insurance) is a valid risk transfer mechanism because the organization pays a premium to shift the financial impact of covered cyber events, such as data breaches or ransomware, to the insurer. Option E (Outsourcing with liability clauses) is also valid risk transfer because contractual liability clauses shift specified responsibilities and financial consequences for incidents to the third-party vendor. Option A (Accepting the risk with sign-off) is risk acceptance, not transfer, since the organization retains the risk. Option C (Implementing access controls) is risk mitigation/reduction through preventive controls. Option D (Discontinuing the project) is risk avoidance, as the activity creating the risk is eliminated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accepting the risk with sign-off
Why it's wrong here
Accepting the risk with sign-off is retention, not transfer, because the organisation keeps the exposure and its financial consequences. It is tempting because documented acceptance is a formal risk response, but transfer needs a counterparty — insurance, indemnity or outsourcing — to bear the loss instead.
- ✓
Purchasing cyber insurance
Why this is correct
Cyber insurance transfers the financial impact of a realised risk to the insurer in exchange for premiums, leaving the organisation to bear only deductibles and uncovered losses. This satisfies the stem's requirement for a valid risk transfer mechanism, since the monetary consequence, not the risk itself, is shifted.
- ✗
Implementing access controls
Why it's wrong here
Access controls are a preventive mitigation that reduces likelihood, leaving the residual risk with the organisation rather than moving it. It is tempting because controls are a recognised risk response, but that response is mitigation; transfer requires an insurer or third party contractually absorbing the financial impact.
- ✗
Discontinuing the project
Why it's wrong here
Discontinuing the project eliminates the risk through avoidance, not transfer, since no third party assumes the exposure. It is tempting because cancelling removes the firm's liability, but that is risk avoidance; transfer requires another party, such as an insurer or outsourced provider, contractually accepting the loss.
- ✓
Outsourcing with liability clauses
Why this is correct
Outsourcing shifts the operational risk of delivering the project to a third party, and the liability clauses in the contract transfer the financial consequence back to that vendor if failures occur. This satisfies the stem's requirement for a valid risk transfer mechanism by moving both responsibility and impact off the organisation.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.