CRISC Risk Response and Mitigation Practice Question
A financial services firm's risk register shows that a critical trading application has a high inherent risk of unauthorized access. The risk owner decides to implement multifactor authentication (MFA) and role-based access controls (RBAC). After implementation, the residual risk score decreases but remains above the risk appetite. Which of the following should the risk practitioner recommend NEXT?
⚠ Common exam trap
The trap here is assuming that any reduction in risk after implementing controls is sufficient, even if residual risk remains above the risk appetite.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform additional risk response to further reduce the residual risk to within appetite.
The correct answer is to perform additional risk response because residual risk still exceeds the risk appetite. CRISC emphasizes that risk treatment is iterative: after controls are applied, if residual risk is not within appetite, further action is needed. This could include additional controls, risk avoidance, or transfer, but the key is to continue treatment until risk is acceptable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Perform additional risk response to further reduce the residual risk to within appetite.
Why this is correct
When residual risk remains above the risk appetite after implementing controls, the risk practitioner should recommend further risk response, such as additional controls, risk transfer, or avoidance. This aligns with the CRISC principle of continuous risk treatment until risk is within acceptable levels, ensuring alignment with organizational objectives.
- ✗
Accept the residual risk because the controls have reduced it significantly.
Why it's wrong here
Accepting residual risk that remains above the risk appetite is inappropriate unless the risk owner has authority and explicitly documents the acceptance with a time-bound remediation plan. Here, the risk still exceeds appetite, so acceptance without further action would leave the organization exposed and violate risk governance principles.
- ✗
Remove the existing controls and reassess the inherent risk.
Why it's wrong here
Removing controls would increase risk exposure and is counterproductive. The existing controls have already reduced risk; the goal is to build on them, not eliminate them. Reassessing inherent risk does not address the current residual risk exceeding appetite.
- ✗
Transfer the entire risk to a third party through insurance.
Why it's wrong here
Risk transfer via insurance may be part of a response, but it does not reduce the likelihood or impact of unauthorized access itself; it only compensates for financial loss. The residual risk from operational exposure remains, and transferring the entire risk is rarely feasible or sufficient to bring risk within appetite.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.