CRISC IT Risk Assessment Practice Question
A hospital's IT risk register lists a risk that its medical imaging archive could become unavailable. The risk owner has documented the risk, set a review date, and decided to take no action because the potential impact is within the hospital's risk appetite. Which risk treatment option has the risk owner selected?
⚠ Common exam trap
The trap here is assuming that taking no action is always negligence, when a documented, owner-assigned, review-scheduled decision within appetite is the legitimate treatment known as acceptance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk acceptance
Formal risk acceptance occurs when an organization decides to retain a risk because it falls within the defined risk appetite, while documenting the decision, assigning an owner, and scheduling periodic review. The hospital's actions match this pattern precisely. Mitigation would add controls, avoidance would remove the activity, and transfer would shift the impact to a third party; none of those occurred, so acceptance is the correct characterization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk mitigation
Why it's wrong here
Mitigation means implementing controls to reduce likelihood or impact, such as redundant storage or a failover site for the imaging archive. The owner here explicitly decided to take no action, so no controls were added and the risk exposure remains unchanged. Choosing mitigation would require the owner to select and fund controls and then reassess residual risk, which is not what the documented decision describes.
- ✓
Risk acceptance
Why this is correct
Acceptance is the deliberate decision to retain a risk without additional treatment when it falls within the organization's risk appetite. Documenting the risk, assigning an owner, and setting a review date are the hallmarks of formal acceptance, because the organization retains awareness and re-evaluates if conditions change. The hospital's decision matches this definition exactly: no action taken, exposure acknowledged, and the risk remains on the register.
- ✗
Risk transfer
Why it's wrong here
Transfer shifts the financial consequence to a third party, typically through insurance or contractual indemnities. Nothing in the scenario indicates a policy, warranty, or outsourcing agreement was arranged for the imaging archive. The owner simply documented the risk and took no action, meaning the hospital still bears the full impact if the archive becomes unavailable. Transfer would require an explicit third-party arrangement that is absent here.
- ✗
Risk avoidance
Why it's wrong here
Avoidance means eliminating the activity or asset that generates the risk, for example decommissioning the imaging archive or moving imaging to an external service and discontinuing the internal system. The owner here retained the archive and continued operating it, so the risk source was not removed. Avoidance is typically chosen when no treatment can bring risk within appetite, which is not the situation described.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.