Courseiva

CRISC Risk Response and Reporting Practice Question

A healthcare provider has determined that a new telehealth platform introduces risks that exceed its defined risk tolerance. Senior management decides to purchase cyber insurance to cover potential breach costs rather than modify the platform. Which risk response is management applying?

⚠ Common exam trap

Watch out — candidates often confuse risk transfer with risk acceptance because the underlying platform risk remains in place even though insurance was purchased.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk transfer

Insurance shifts the financial burden of a potential breach to the insurer, which is the defining characteristic of risk transfer. The telehealth platform continues to operate, so the risk is not avoided, and no technical control was added, so it is not mitigated. Because management acted rather than simply tolerating the exposure, acceptance does not apply.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk transfer

    Why this is correct

    Transfer shifts the financial consequences of a risk to a third party, and insurance is the classic example. By purchasing coverage, management retains the operational risk but moves the monetary impact of a breach to the insurer. This matches the decision to keep the platform while offloading financial exposure.

  • ✗

    Risk avoidance

    Why it's wrong here

    Avoidance means eliminating the activity that generates the risk, for example by not deploying the telehealth platform at all. Management chose to proceed with the platform while addressing the financial exposure, so the risk-generating activity remains. Avoidance would have required canceling or fundamentally changing the initiative.

  • ✗

    Risk acceptance

    Why it's wrong here

    Acceptance means acknowledging the risk and taking no action to change likelihood, impact, or financial exposure. Management did take action by buying a policy, so the risk is not simply accepted. Acceptance is documented through a formal risk acceptance decision, which is absent here.

  • ✗

    Risk mitigation

    Why it's wrong here

    Mitigation reduces the likelihood or impact of a risk through controls such as patching, segmentation, or encryption. Purchasing insurance does not change the probability of a breach or reduce its technical impact; it compensates for financial consequences after the fact. Therefore mitigation does not describe the action management took in this scenario.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.