Courseiva

CRISC Risk Response and Mitigation Practice Question

A retail company is launching a new mobile payment application. The risk practitioner is identifying risk response options for the risk of payment fraud. Which TWO of the following are examples of risk mitigation controls? (Choose two.)

⚠ Common exam trap

Watch out — candidates often confuse risk transfer or avoidance with mitigation; controls that reduce likelihood or impact are mitigation, while insurance and avoidance are different strategies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tokenization of payment card data

Tokenization and real-time fraud detection are both mitigation controls because they actively reduce the risk of payment fraud. Tokenization minimizes the value of stolen data, while fraud detection identifies and blocks suspicious transactions. The other options represent risk transfer, risk avoidance, and risk acceptance, which do not reduce the inherent risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Tokenization of payment card data

    Why this is correct

    Tokenization replaces sensitive card data with non-sensitive tokens, reducing the impact of a data breach. It is a preventive control that mitigates the risk of payment fraud by making stolen tokens useless to attackers. This is a classic risk mitigation technique that reduces both likelihood and impact.

  • ✓

    Implementing real-time fraud detection algorithms

    Why this is correct

    Real-time fraud detection monitors transactions and flags suspicious activity, allowing the organization to block fraudulent payments before they complete. This is a detective and preventive control that directly reduces the likelihood of successful fraud. It is a mitigation measure because it actively intervenes to stop fraud.

  • ✗

    Accepting the risk of fraud and monitoring it quarterly

    Why it's wrong here

    Acceptance means acknowledging the risk and taking no action to reduce it. Monitoring does not mitigate the risk; it simply tracks it. This is a risk acceptance strategy, not a mitigation control. It does not reduce the likelihood or impact of payment fraud.

  • ✗

    Deciding not to offer mobile payments in certain countries

    Why it's wrong here

    Deciding not to offer the service in certain regions is risk avoidance, not mitigation. Avoidance eliminates the risk by not engaging in the activity, whereas mitigation reduces risk while continuing the activity. This option does not control fraud in the countries where the service is offered.

  • ✗

    Purchasing cyber insurance to cover fraud losses

    Why it's wrong here

    Cyber insurance transfers the financial impact of fraud but does not reduce the likelihood or technical impact of the fraud itself. It is a risk transfer strategy, not a mitigation control. While valuable, it does not prevent fraudulent transactions from occurring.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.