Courseiva
IT Risk Assessment →hardMultiple Choice

CRISC IT Risk Assessment Practice Question

A healthcare organization is assessing the risk of a ransomware attack on its electronic health record (EHR) system. The risk team has identified that the organization performs daily incremental backups and weekly full backups, but the backups are stored on the same network share as the EHR data. The risk owner argues that the backup strategy reduces the impact of a ransomware attack. Which statement BEST describes the residual risk after considering this control?

⚠ Common exam trap

The trap here is assuming that any backup strategy reduces risk, without considering whether the backups are isolated from the threat.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The residual risk is high because the backups are not isolated and could be encrypted along with the primary data.

The backup strategy is ineffective against ransomware because the backups reside on the same network share as the primary EHR data. Ransomware can encrypt both, so the organization may lose both primary and backup data. Therefore, the residual risk remains high. The risk practitioner should recognize this control weakness and recommend isolating backups, such as using offline or immutable storage. This is a critical aspect of IT risk assessment: evaluating control effectiveness, not just existence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The residual risk is unchanged from the inherent risk because backups are a preventive control.

    Why it's wrong here

    Backups are a corrective/recovery control, not preventive. They do not prevent the ransomware attack but can help restore data. However, because they are on the same network share, their corrective value is negated. The residual risk is not unchanged; it may be slightly reduced if some backups survive, but overall it remains high. The statement misclassifies the control type and ignores the shared storage vulnerability.

  • ✗

    The residual risk is medium because the weekly full backup provides a fallback if incremental backups fail.

    Why it's wrong here

    The weekly full backup is also on the same network share, so it is equally vulnerable to ransomware encryption. The frequency of backups does not mitigate the risk if they are not isolated. The residual risk is not reduced to medium; it remains high due to the shared storage. The risk practitioner must assess the effectiveness of the control, not just its existence. The backup strategy as described does not provide adequate protection.

  • ✗

    The residual risk is low because daily backups ensure data can be restored with minimal loss.

    Why it's wrong here

    Daily backups alone do not guarantee low residual risk if the backups are stored on the same network share. Ransomware can encrypt both the primary data and the backups, rendering them useless. The control is ineffective against ransomware that targets connected storage. Therefore, the residual risk remains high because the backup integrity is compromised. The risk owner's argument overlooks this critical vulnerability in the backup design.

  • ✓

    The residual risk is high because the backups are not isolated and could be encrypted along with the primary data.

    Why this is correct

    Storing backups on the same network share as the primary data means ransomware can encrypt both, eliminating the recovery benefit. The control is not effective in reducing impact. Thus, the residual risk remains high. This is a common pitfall in backup strategies; best practice is to keep offline or immutable backups. The risk practitioner should identify this as a control weakness and recommend remediation.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.