Courseiva

CRISC Risk Response and Mitigation Practice Question

A financial services firm has a critical web application that must remain available 24/7. The risk assessment indicates that a distributed denial-of-service (DDoS) attack could cause significant downtime. The risk owner decides to implement a cloud-based DDoS mitigation service that scrubs traffic before it reaches the application. Which risk response strategy does this represent?

⚠ Common exam trap

Candidates often confuse the use of a third-party service with risk transference, when in fact the service is a mitigation control that reduces risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk mitigation

Implementing a DDoS mitigation service is a classic example of risk mitigation because it reduces the likelihood or impact of a threat. The risk is not avoided (the service continues), not transferred (the firm retains responsibility), and not accepted (action is taken). Mitigation controls are designed to bring residual risk within the organization's risk appetite.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk avoidance

    Why it's wrong here

    Risk avoidance involves eliminating the activity or condition that gives rise to the risk entirely. Here, the firm continues to operate the web application, so it has not avoided the risk. Instead, it has taken steps to reduce the impact or likelihood of a DDoS attack. Avoidance would mean discontinuing the online service altogether, which is not the case.

  • ✗

    Risk acceptance

    Why it's wrong here

    Risk acceptance means acknowledging the risk and deciding to bear the potential consequences without taking further action. In this scenario, the firm is actively implementing a mitigation service, which contradicts acceptance. Acceptance would involve no additional controls and simply monitoring the risk, which is not what is happening here.

  • ✗

    Risk transference

    Why it's wrong here

    Risk transference shifts the financial impact of a risk to a third party, typically through insurance or outsourcing. While the firm uses a cloud service, the responsibility for the application's availability and the potential reputational damage remains with the firm. The DDoS mitigation service reduces the risk rather than transferring the financial consequences to another party.

  • ✓

    Risk mitigation

    Why this is correct

    Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. By deploying a cloud-based DDoS mitigation service, the firm adds a control that scrubs malicious traffic, thereby reducing the chance of downtime and lessening the impact of an attack. This aligns with the definition of risk mitigation, as the risk is still present but its effect is diminished.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.