CRISC Risk Response and Mitigation Practice Question
A healthcare organization has identified that its patient portal has a vulnerability that could expose sensitive data. The risk owner decides to implement multifactor authentication (MFA) for all users. After implementation, the risk practitioner conducts a follow-up assessment and finds that some users are sharing credentials, potentially bypassing MFA. The risk practitioner should FIRST:
⚠ Common exam trap
The trap here is jumping to a solution like training or new controls without first reassessing the risk and informing the risk owner.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the control failure to the risk owner and reassess the residual risk.
When a control is found to be ineffective or circumvented, the risk practitioner must first report the control failure to the risk owner and reassess the residual risk. This ensures that the risk owner is aware of the changed risk landscape and can make an informed decision on whether to accept, mitigate, or transfer the risk. The reassessment should consider the extent of credential sharing, its impact on the MFA control's effectiveness, and any additional vulnerabilities. Only after this reassessment should further actions, such as training or technical controls, be considered.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Report the control failure to the risk owner and reassess the residual risk.
Why this is correct
The risk practitioner's first step is to inform the risk owner that the implemented control (MFA) is not fully effective due to credential sharing. This triggers a reassessment of the residual risk, as the control may no longer reduce risk to an acceptable level. The practitioner should gather evidence, quantify the impact, and present findings to the risk owner so that a decision can be made on additional risk responses, such as stricter enforcement or alternative controls.
- ✗
Recommend additional security awareness training for all users.
Why it's wrong here
Security awareness training is a valid control, but it is not the first action. The immediate concern is that the MFA control is being circumvented, which means the residual risk may still be high. The practitioner should first assess the extent and impact of the credential sharing to determine if the risk response is still effective. Training may be part of the solution, but it should follow a thorough analysis of the control failure.
- ✗
Implement technical controls to prevent credential sharing, such as device fingerprinting.
Why it's wrong here
Implementing new technical controls is typically the responsibility of IT security, not the risk practitioner. Moreover, jumping to a solution without first reassessing the risk and informing the risk owner bypasses proper risk management governance. The practitioner should first analyze the situation and communicate with the risk owner, who may decide on the appropriate course of action, which could include technical measures.
- ✗
Accept the residual risk because MFA is still partially effective.
Why it's wrong here
Accepting residual risk is a decision for the risk owner, not the risk practitioner. Furthermore, accepting risk without a thorough reassessment could be premature. The credential sharing may significantly undermine the MFA control, potentially leaving the organization exposed. The practitioner should not unilaterally accept risk; instead, they should provide the risk owner with an updated risk assessment to inform the acceptance decision.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.