Courseiva

CRISC Risk Response and Mitigation Practice Question

A multinational bank has a risk appetite that allows for a maximum of 5% downtime for its online banking platform per quarter. The platform currently experiences 8% downtime due to frequent distributed denial-of-service (DDoS) attacks. The risk owner proposes investing in a cloud-based DDoS mitigation service. Which of the following should be the risk practitioner's PRIMARY consideration when evaluating this proposed risk response?

⚠ Common exam trap

The trap here is prioritizing cost or vendor reputation over the fundamental question of whether the control actually reduces risk to within appetite.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The expected reduction in downtime and whether it brings residual risk within the bank's risk appetite.

The risk practitioner's primary role is to evaluate whether a proposed risk response will bring residual risk within the organization's risk appetite. Here, the bank's risk appetite for downtime is 5%, but current downtime is 8%. The proposed DDoS mitigation service must be assessed for its ability to reduce downtime to 5% or less. This assessment should consider the service's effectiveness, reliability, and any residual risk. Cost, integration, and vendor reputation are secondary factors that inform the decision but do not replace the core risk-reduction evaluation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The total cost of the service compared to the potential financial losses from downtime.

    Why it's wrong here

    Cost-benefit analysis is important, but it is not the primary consideration. The risk practitioner must first determine if the control can actually reduce risk to an acceptable level. If the service cannot achieve the required downtime reduction, cost becomes irrelevant. Moreover, the risk appetite is a predefined threshold; the practitioner's primary duty is to ensure the response meets that threshold, not to optimize cost.

  • ✗

    The service provider's reputation and market share in the DDoS mitigation industry.

    Why it's wrong here

    While vendor reputation can influence reliability, it is not the primary consideration. The risk practitioner should focus on whether the service can effectively mitigate the risk to within the risk appetite. Reputation may be a factor in due diligence, but it does not guarantee performance. The practitioner must evaluate concrete evidence of the service's ability to reduce downtime, such as SLAs, testing results, and references.

  • ✓

    The expected reduction in downtime and whether it brings residual risk within the bank's risk appetite.

    Why this is correct

    The primary consideration is whether the proposed DDoS mitigation service will reduce the downtime from 8% to 5% or below, aligning with the bank's risk appetite. The risk practitioner must evaluate the control's effectiveness in mitigating the risk to an acceptable level. This involves analyzing the service's capabilities, historical performance, and any residual risk after implementation. Cost and integration are secondary to this fundamental risk-reduction assessment.

  • ✗

    The service provider's ability to integrate with the bank's existing incident response plan.

    Why it's wrong here

    Integration with the incident response plan is important for effective response, but it is not the primary consideration when evaluating a risk response. The primary focus should be on whether the proposed control will reduce the downtime to within the 5% risk appetite. Integration is a secondary operational concern that affects implementation but does not directly determine risk reduction effectiveness.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.