CRISC Risk Response and Reporting Practice Question
A financial services firm's risk register shows that a legacy payment gateway has a high inherent risk of SQL injection. The security team proposes deploying a web application firewall (WAF) in front of the gateway. The risk owner must document how this action will be classified in the risk response plan. Which risk response strategy does deploying the WAF represent?
⚠ Common exam trap
The trap here is assuming that any security control automatically means risk avoidance, when avoidance requires eliminating the activity that creates the risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk mitigation
Applying a web application firewall reduces the likelihood and impact of SQL injection against the legacy payment gateway, which is the definition of risk mitigation. The organization continues to operate the asset and retains the residual risk, so avoidance, transfer, and acceptance do not describe the action. Correct classification matters because the risk register and reporting must reflect the true response strategy and its effect on residual risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Risk mitigation
Why this is correct
Deploying a WAF reduces the likelihood and impact of SQL injection by filtering malicious input before it reaches the payment gateway. In CRISC terms, this is risk mitigation because a control is applied to bring the residual risk within the organization's risk appetite while the underlying asset and threat remain. The risk is not eliminated, transferred, or avoided, so mitigation is the accurate classification.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance means the organization acknowledges the risk and chooses to bear it without additional controls, usually because the cost of treatment exceeds the benefit. The firm is investing in a WAF precisely to change the risk level, so this is an active response rather than acceptance. Documenting it as acceptance would leave the residual risk unmanaged and misaligned with the risk appetite.
- ✗
Risk avoidance
Why it's wrong here
Risk avoidance would require discontinuing the legacy payment gateway or removing the vulnerable functionality entirely. Here the organization continues to operate the gateway and adds a compensating control, so the risk exposure still exists. Avoidance eliminates the activity that creates the risk, which is not what the security team is proposing in this scenario.
- ✗
Risk transfer
Why it's wrong here
Risk transfer shifts the financial consequence of a risk to a third party, typically through insurance, indemnity clauses, or outsourcing. A WAF does not shift loss to another party; it reduces the probability of a successful attack. Since no contractual or insurance mechanism is involved, classifying the WAF as risk transfer would misstate the response in the risk register.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.