CRISC Risk Response and Reporting Practice Question
A healthcare provider has determined that a new telehealth platform introduces risks that exceed its defined risk tolerance. Senior management decides to purchase cyber insurance to cover potential breach costs rather than modify the platform. Which risk response is management applying?
⚠ Common exam trap
Watch out — candidates often confuse risk transfer with risk acceptance because the underlying platform risk remains in place even though insurance was purchased.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk transfer
Insurance shifts the financial burden of a potential breach to the insurer, which is the defining characteristic of risk transfer. The telehealth platform continues to operate, so the risk is not avoided, and no technical control was added, so it is not mitigated. Because management acted rather than simply tolerating the exposure, acceptance does not apply.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Risk transfer
Why this is correct
Transfer shifts the financial consequences of a risk to a third party, and insurance is the classic example. By purchasing coverage, management retains the operational risk but moves the monetary impact of a breach to the insurer. This matches the decision to keep the platform while offloading financial exposure.
- ✗
Risk avoidance
Why it's wrong here
Avoidance means eliminating the activity that generates the risk, for example by not deploying the telehealth platform at all. Management chose to proceed with the platform while addressing the financial exposure, so the risk-generating activity remains. Avoidance would have required canceling or fundamentally changing the initiative.
- ✗
Risk acceptance
Why it's wrong here
Acceptance means acknowledging the risk and taking no action to change likelihood, impact, or financial exposure. Management did take action by buying a policy, so the risk is not simply accepted. Acceptance is documented through a formal risk acceptance decision, which is absent here.
- ✗
Risk mitigation
Why it's wrong here
Mitigation reduces the likelihood or impact of a risk through controls such as patching, segmentation, or encryption. Purchasing insurance does not change the probability of a breach or reduce its technical impact; it compensates for financial consequences after the fact. Therefore mitigation does not describe the action management took in this scenario.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.