Courseiva

CRISC Risk Response and Mitigation Practice Question

A financial institution is implementing a new online banking platform. The risk assessment identified that the platform will handle sensitive customer data and must comply with GDPR and local banking regulations. The project team proposes encrypting all data at rest and in transit, implementing multi-factor authentication (MFA), and conducting quarterly penetration tests. However, the risk owner is concerned about the residual risk of a sophisticated phishing attack that could bypass MFA. The board has a low risk appetite. What is the BEST way to address this residual risk?

⚠ Common exam trap

CRISC often tests the distinction between risk response types (avoid, mitigate, transfer, accept) — candidates pick insurance (transfer) or acceptance because they sound pragmatic, but a low risk appetite plus an identified residual risk demands a mitigation answer that reduces likelihood, not one that merely moves or tolerates the impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement advanced phishing-resistant MFA (e.g., FIDO2) and conduct regular employee phishing simulation training.

The residual risk is a sophisticated phishing attack that could bypass MFA, and the board has a low risk appetite, so the risk must be reduced rather than transferred or accepted. Implementing phishing-resistant MFA such as FIDO2/WebAuthn (hardware security keys or passkeys) removes the shared-secret and OTP weaknesses that phishing kits exploit, and pairing it with ongoing phishing simulation training hardens the human layer. This directly addresses the specific residual risk while preserving the business value of the online banking platform.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Purchase cyber insurance to transfer the financial impact of a potential phishing attack.

    Why it's wrong here

    Insurance transfers financial consequence only; it leaves the likelihood of credential compromise and unauthorised data access unchanged, so residual risk still exceeds the board's low appetite. Transfer is appropriate for low-frequency, high-severity losses where the organisation prefers to cap financial exposure rather than invest further in preventive controls.

  • ✓

    Implement advanced phishing-resistant MFA (e.g., FIDO2) and conduct regular employee phishing simulation training.

    Why this is correct

    Phishing-resistant MFA such as FIDO2 uses origin-bound cryptographic credentials that cannot be replayed by proxy phishing sites, directly mitigating the MFA-bypass residual risk. Combining it with simulation training addresses the human factor, aligning treatment with the board's low risk appetite.

  • ✗

    Reduce the project scope to exclude online banking and revert to a less risky channel.

    Why it's wrong here

    Cancelling the platform removes the business capability entirely rather than treating the phishing residual risk; risk response should modify the exposure, not abandon the initiative. Scope reduction is correct when a specific component's risk cannot be mitigated within appetite and the function is genuinely dispensable.

  • ✗

    Accept the residual risk because the existing controls (encryption, MFA, pen tests) already provide reasonable assurance.

    Why it's wrong here

    Acceptance contradicts the board's low risk appetite, and the residual phishing exposure remains unmitigated rather than evaluated against defined tolerance. Acceptance is the correct response only when residual risk falls within the organisation's stated risk appetite after all cost-effective treatments are applied, which is not the case here.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.