Courseiva

CRISC Risk Response and Mitigation Practice Question

A financial services firm's risk register shows that a critical trading application has a high inherent risk of unauthorized access. The risk owner decides to implement multifactor authentication (MFA) and role-based access controls (RBAC). After implementation, the residual risk score decreases but remains above the risk appetite. Which of the following should the risk practitioner recommend NEXT?

⚠ Common exam trap

The trap here is assuming that any reduction in risk after implementing controls is sufficient, even if residual risk remains above the risk appetite.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform additional risk response to further reduce the residual risk to within appetite.

The correct answer is to perform additional risk response because residual risk still exceeds the risk appetite. CRISC emphasizes that risk treatment is iterative: after controls are applied, if residual risk is not within appetite, further action is needed. This could include additional controls, risk avoidance, or transfer, but the key is to continue treatment until risk is acceptable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Perform additional risk response to further reduce the residual risk to within appetite.

    Why this is correct

    When residual risk remains above the risk appetite after implementing controls, the risk practitioner should recommend further risk response, such as additional controls, risk transfer, or avoidance. This aligns with the CRISC principle of continuous risk treatment until risk is within acceptable levels, ensuring alignment with organizational objectives.

  • ✗

    Accept the residual risk because the controls have reduced it significantly.

    Why it's wrong here

    Accepting residual risk that remains above the risk appetite is inappropriate unless the risk owner has authority and explicitly documents the acceptance with a time-bound remediation plan. Here, the risk still exceeds appetite, so acceptance without further action would leave the organization exposed and violate risk governance principles.

  • ✗

    Remove the existing controls and reassess the inherent risk.

    Why it's wrong here

    Removing controls would increase risk exposure and is counterproductive. The existing controls have already reduced risk; the goal is to build on them, not eliminate them. Reassessing inherent risk does not address the current residual risk exceeding appetite.

  • ✗

    Transfer the entire risk to a third party through insurance.

    Why it's wrong here

    Risk transfer via insurance may be part of a response, but it does not reduce the likelihood or impact of unauthorized access itself; it only compensates for financial loss. The residual risk from operational exposure remains, and transferring the entire risk is rarely feasible or sufficient to bring risk within appetite.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.