Courseiva
Risk Response and Reporting →mediumMultiple Choice

CRISC Risk Response and Reporting Practice Question

A logistics firm relies on a third-party cloud provider to host its shipment tracking system. The provider's latest SOC 2 report includes a qualified opinion noting that access review controls were not operating effectively during part of the audit period. The firm's risk practitioner must determine the appropriate risk response. Which of the following is the MOST appropriate action?

⚠ Common exam trap

The trap here is treating the existence of a SOC 2 report as assurance of effective controls, when a qualified opinion specifically documents a control failure that requires its own risk response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assess the impact of the access review exception on the firm's data and implement compensating controls while the provider remediates.

A qualified SOC 2 opinion identifies a real control failure at the provider, so the firm cannot simply accept the risk or wait a year for the next report. The practitioner should assess how the access review weakness affects the shipment tracking data and deploy compensating controls during remediation. This protects the firm while preserving the vendor relationship and allows for a proportionate, evidence-based response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Terminate the contract immediately and migrate the shipment tracking system to a different provider.

    Why it's wrong here

    Immediate termination is a disproportionate response that ignores cost, transition risk, and the possibility that compensating controls can mitigate the exposure. Migration itself introduces significant operational and security risk. A measured response should first assess the impact of the access review failure on the firm's data and determine whether interim controls or contractual remedies are sufficient.

  • ✓

    Assess the impact of the access review exception on the firm's data and implement compensating controls while the provider remediates.

    Why this is correct

    The qualified opinion signals a specific control weakness, so the practitioner should evaluate how that weakness affects the logistics firm's data and systems. Implementing compensating controls, such as additional monitoring or restricting privileged access, reduces exposure while the provider addresses the root cause. This response is proportionate, risk-based, and maintains service continuity while holding the provider accountable.

  • ✗

    Request the provider's remediation plan and take no further action until the next annual SOC 2 report is issued.

    Why it's wrong here

    Waiting a full year for the next report leaves the firm exposed to the identified access review weakness in the interim. Requesting a remediation plan is useful, but it does not by itself reduce risk. The practitioner should combine the request with compensating controls and monitoring to manage the exposure during the remediation period, rather than relying solely on future assurance.

  • ✗

    Accept the risk because the provider holds a SOC 2 report, which demonstrates an adequate control environment.

    Why it's wrong here

    A SOC 2 report with a qualified opinion does not demonstrate an adequate control environment for the affected period; it explicitly identifies a control failure. Accepting the risk based on the existence of the report misreads its purpose. The practitioner must evaluate the specific exception, its impact on the shipment tracking system, and whether compensating controls reduce the exposure before deciding on a response.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.