Courseiva

CRISC Risk Response and Mitigation Practice Question

A new privacy regulation requires that all personal data be encrypted at rest. The current systems lack encryption. The cost to implement encryption is moderate, and the risk of non-compliance is high. Which risk response is most appropriate?

⚠ Common exam trap

CRISC often tests the misconception that transferring risk via insurance is sufficient for compliance, or that acceptance is viable when the risk is high; candidates must recognize that mitigation is the correct response when the cost is reasonable and the risk is significant.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mitigate by implementing encryption

Mitigating the risk by implementing encryption is the most appropriate response because the cost is moderate and the risk of non-compliance is high. Encryption directly addresses the regulatory requirement and reduces the risk to an acceptable level. This aligns with risk management principles where high-impact risks with feasible controls should be mitigated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Mitigate by implementing encryption

    Why this is correct

    Implementing encryption directly removes the regulatory exposure, satisfying the requirement that personal data be encrypted at rest. With moderate cost against high non-compliance risk, mitigation offers the best value; acceptance, avoidance or transfer would leave the legal obligation unmet. Encryption is the precise control the regulation mandates.

  • ✗

    Accept the risk

    Why it's wrong here

    Acceptance leaves personal data unencrypted and the high non-compliance risk intact, breaching the regulation's mandatory requirement. Acceptance is the correct response only when the risk falls within tolerance and no cost-effective treatment exists, which the moderate encryption cost contradicts.

  • ✗

    Avoid by discontinuing data processing

    Why it's wrong here

    Discontinuing processing eliminates the regulatory obligation but destroys the business capability the data supports, which is disproportionate when encryption costs are only moderate. Avoidance suits scenarios where the activity itself is unlawful or the residual risk cannot be reduced to acceptable levels.

  • ✗

    Transfer via cyber insurance

    Why it's wrong here

    Cyber insurance compensates financial loss after a breach but does not encrypt data at rest, so the regulatory requirement remains unmet. Transfer suits risks whose financial impact can be shifted, such as residual breach costs, not mandatory technical controls the organisation must implement itself.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.