Courseiva

CRISC Risk Response and Reporting Practice Question

A global retailer's risk committee is reviewing a proposal to transfer the financial impact of payment card fraud to an insurer through a cyber insurance policy. The policy has a $2 million retention and excludes losses caused by unencrypted cardholder data at rest. The organization's cardholder database is currently unencrypted. Which of the following is the MOST significant limitation the risk manager should highlight?

⚠ Common exam trap

The trap here is assuming that purchasing a cyber insurance policy automatically transfers the relevant fraud risk without checking policy exclusions against the actual control state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The exclusion for unencrypted cardholder data means the transfer will not respond to a loss from the current database configuration.

Transferring risk through insurance is effective only when the loss event is actually covered. An exclusion for unencrypted cardholder data at rest directly conflicts with the current state of the cardholder database, so a breach of that database would not be indemnified. The risk manager must flag this gap so the committee understands that the proposed transfer does not address the organization's most likely fraud loss scenario, and that encryption or another response is needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cyber insurance cannot be used as a risk response because it does not reduce the likelihood of a fraud event.

    Why it's wrong here

    Risk transfer is a recognized response that addresses financial impact rather than likelihood, so the fact that insurance does not prevent fraud is not a valid criticism. CRISC explicitly treats transfer as a legitimate option alongside avoid, mitigate, and accept. Rejecting insurance for not reducing likelihood misapplies the purpose of transfer and could steer the committee away from a useful financial protection instrument.

  • ✓

    The exclusion for unencrypted cardholder data means the transfer will not respond to a loss from the current database configuration.

    Why this is correct

    Risk transfer only works when the transferred event falls within the policy's coverage. Because the cardholder database is unencrypted and the policy excludes losses from unencrypted data at rest, a breach of that database would fall outside coverage, leaving the organization to bear the full financial impact. This is the material limitation the committee must weigh before treating insurance as the response.

  • ✗

    The insurer, not the risk committee, will now own the risk and control decisions for the payment environment.

    Why it's wrong here

    Transferring financial impact to an insurer does not transfer ownership of the risk or authority over controls; the organization remains accountable for managing the exposure and complying with policy conditions. Insurers may impose requirements, but accountability stays with the retailer. This option reflects a common misunderstanding that insurance outsources risk ownership, which would distort governance and accountability if acted upon.

  • ✗

    The retention amount is too low to provide meaningful financial protection for a global retailer.

    Why it's wrong here

    Retention levels are negotiated based on the organization's capacity to absorb losses, and a $2 million retention is not inherently too low for a retailer. The more decisive issue is that the policy will not respond at all to a loss arising from the unencrypted database, regardless of retention size. Focusing on retention misses the exclusion that could render the transfer ineffective for the very scenario the retailer faces.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.