CRISC IT Risk Assessment Practice Question
A healthcare organization is assessing the risk of a ransomware attack on its electronic health record (EHR) system. The risk assessment team has identified that the likelihood of an attack is high due to recent industry trends, and the impact would be severe, including patient safety risks and regulatory fines. The organization has a limited budget and wants to implement controls that provide the greatest risk reduction. Which of the following risk response strategies is MOST appropriate in this scenario?
⚠ Common exam trap
The trap here is assuming that cyber insurance (risk transfer) fully addresses the risk, when it only covers financial losses and does not prevent operational disruption or patient harm.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk mitigation by implementing layered controls such as regular backups, employee training, and endpoint detection and response.
Risk mitigation is the most appropriate strategy because it reduces both the likelihood and impact of a ransomware attack through layered controls. Given the criticality of the EHR system and the severe consequences, simply transferring or accepting the risk would leave the organization vulnerable. Avoidance is impractical. Mitigation aligns with the need to protect patient safety and comply with regulations while operating within budget constraints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk acceptance by documenting the risk and taking no action due to budget constraints.
Why it's wrong here
Risk acceptance means acknowledging the risk and deciding not to act. However, given the high likelihood, severe impact, and regulatory obligations, accepting the risk without any controls would be irresponsible. It could lead to patient harm, legal penalties, and reputational damage. Acceptance is only appropriate when the risk is within the organization's risk appetite and no cost-effective controls exist, which is not the case here.
- ✓
Risk mitigation by implementing layered controls such as regular backups, employee training, and endpoint detection and response.
Why this is correct
Risk mitigation reduces the likelihood or impact of a risk through controls. For ransomware, layered controls like offline backups, security awareness training, and endpoint detection can significantly reduce the chance of a successful attack and enable rapid recovery. Given the high likelihood and severe impact, mitigation is the most practical strategy to protect patient safety and meet regulatory requirements without halting essential operations.
- ✗
Risk transfer by purchasing cyber insurance to cover all potential losses.
Why it's wrong here
Risk transfer shifts the financial impact to a third party, such as an insurer. While cyber insurance can help with recovery costs, it does not reduce the likelihood of an attack or the operational and patient safety impacts. Ransomware can still disrupt care and cause regulatory penalties. Insurance alone is insufficient; mitigation is needed to prevent and respond to attacks. Transfer is a complement, not a primary strategy here.
- ✗
Risk avoidance by discontinuing the use of the EHR system.
Why it's wrong here
Risk avoidance would mean eliminating the activity that introduces the risk, such as discontinuing the EHR system. However, EHR is essential for patient care and regulatory compliance, so avoidance is not feasible. It would disrupt operations and likely cause more harm than the risk itself. Avoidance is typically used when the risk is too high and the activity is not critical, which is not the case here.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.