CRISC Risk Response and Reporting Practice Question
A healthcare payer's risk committee is deciding how to respond to a risk that its cloud-hosted claims processing platform could become unavailable for more than 24 hours. The platform is critical, the provider offers a financially backed 99.95% availability commitment, and the organization lacks the internal capability to run a secondary environment. Which risk response is MOST appropriate?
⚠ Common exam trap
The trap here is treating a financially backed availability commitment as equivalent to actual recovery capability, when it only compensates loss and does not restore the service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transfer the financial consequence through contract terms and insurance while implementing a tested recovery capability with the provider.
For a critical platform with no internal recovery capability, the realistic response is layered: contractual remedies and insurance transfer the financial loss, while provider-supported recovery arrangements mitigate the operational outage. Pure acceptance leaves patients and regulators exposed, avoidance is disproportionate, and a stronger SLA alone changes expectations without building the capability to restore service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Transfer the financial consequence through contract terms and insurance while implementing a tested recovery capability with the provider.
Why this is correct
Because internal capability is absent, the practical response combines transferring financial exposure via contractual remedies and cyber or business interruption insurance with mitigating operational impact through provider-supported recovery arrangements that are regularly tested. This layered approach addresses both the monetary loss and the service restoration gap, which is what the committee actually needs for a critical platform.
- ✗
Avoid the risk entirely by terminating the cloud contract and rebuilding the claims platform in an internally managed data center.
Why it's wrong here
Avoidance eliminates the specific cloud dependency but introduces far larger execution, cost, and transition risks, and the organization already lacks the capability to run a secondary environment, let alone a primary one. Avoidance is disproportionate here and would create new continuity and compliance exposures during migration, making it an impractical response for a critical production platform.
- ✗
Accept the risk and document the decision, relying on the provider's service level agreement as the sole safeguard.
Why it's wrong here
Acceptance without compensating measures is inappropriate for a critical platform where the organization retains accountability for claims processing. A contractual availability commitment compensates financially but does not restore service, and regulators still hold the payer responsible for continuity. Acceptance should follow, not replace, mitigation and transfer activities for a risk of this severity.
- ✗
Reduce the risk by negotiating a higher availability percentage in the service level agreement without adding recovery arrangements.
Why it's wrong here
A higher uptime percentage improves expectations but does not create the missing recovery capability. If the platform is unavailable, the payer still cannot process claims regardless of the contractual target, and service credits do not restore operations. Mitigation requires actual recovery mechanisms and testing, not just a stronger number in the agreement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.