CRISC Risk Response and Mitigation Practice Question
A new privacy regulation requires that all personal data be encrypted at rest. The current systems lack encryption. The cost to implement encryption is moderate, and the risk of non-compliance is high. Which risk response is most appropriate?
⚠ Common exam trap
CRISC often tests the misconception that transferring risk via insurance is sufficient for compliance, or that acceptance is viable when the risk is high; candidates must recognize that mitigation is the correct response when the cost is reasonable and the risk is significant.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mitigate by implementing encryption
Mitigating the risk by implementing encryption is the most appropriate response because the cost is moderate and the risk of non-compliance is high. Encryption directly addresses the regulatory requirement and reduces the risk to an acceptable level. This aligns with risk management principles where high-impact risks with feasible controls should be mitigated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Mitigate by implementing encryption
Why this is correct
Implementing encryption directly removes the regulatory exposure, satisfying the requirement that personal data be encrypted at rest. With moderate cost against high non-compliance risk, mitigation offers the best value; acceptance, avoidance or transfer would leave the legal obligation unmet. Encryption is the precise control the regulation mandates.
- ✗
Accept the risk
Why it's wrong here
Acceptance leaves personal data unencrypted and the high non-compliance risk intact, breaching the regulation's mandatory requirement. Acceptance is the correct response only when the risk falls within tolerance and no cost-effective treatment exists, which the moderate encryption cost contradicts.
- ✗
Avoid by discontinuing data processing
Why it's wrong here
Discontinuing processing eliminates the regulatory obligation but destroys the business capability the data supports, which is disproportionate when encryption costs are only moderate. Avoidance suits scenarios where the activity itself is unlawful or the residual risk cannot be reduced to acceptable levels.
- ✗
Transfer via cyber insurance
Why it's wrong here
Cyber insurance compensates financial loss after a breach but does not encrypt data at rest, so the regulatory requirement remains unmet. Transfer suits risks whose financial impact can be shifted, such as residual breach costs, not mandatory technical controls the organisation must implement itself.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.