CRISC Information Technology and Security Practice Question
A retail company's risk register lists 'unauthorized access to the customer loyalty database' with a likelihood of 4 and an impact of 5 on a 1-5 scale. The CISO asks the risk practitioner to reduce the risk to an acceptable level. Which action BEST represents risk treatment in this situation?
⚠ Common exam trap
Watch out — candidates often confuse activities that document, escalate or transfer risk with activities that actually modify the risk itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy database activity monitoring and enforce least-privilege access to the loyalty database.
Risk treatment means selecting and applying controls that change the likelihood or impact of an identified risk. Enforcing least privilege and monitoring database activity directly reduce the chance of unauthorized access, which is the likelihood dimension in the register. Re-scoring, escalation and insurance are assessment, governance and transfer activities that leave the underlying exposure unchanged.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Report the risk to the board risk committee and request a decision on acceptance.
Why it's wrong here
Escalating for a decision is part of risk governance and may result in acceptance, but it does not itself reduce the risk. Until a treatment is chosen and implemented, the exposure stays at the assessed level, so this is a communication step rather than the control action the CISO requested.
- ✗
Recalculate the likelihood and impact scores with the database team and update the risk register.
Why it's wrong here
Re-scoring and documenting the risk is risk assessment and communication, not treatment. It changes the recorded values but does nothing to alter the actual exposure of the loyalty database, so the underlying likelihood of unauthorized access remains unchanged. The scenario explicitly asks for action that reduces the risk to an acceptable level.
- ✓
Deploy database activity monitoring and enforce least-privilege access to the loyalty database.
Why this is correct
Risk treatment is the deliberate selection and implementation of controls that modify likelihood or impact. Database activity monitoring detects anomalous access while least-privilege enforcement reduces the chance that compromised accounts can reach sensitive records, directly lowering the likelihood component of the registered risk. This is a concrete, targeted control response rather than documentation or measurement activity.
- ✗
Purchase a cyber insurance policy that covers privacy breach response costs.
Why it's wrong here
Insurance transfers some financial consequence after an incident but does not lower the likelihood of unauthorized access to the loyalty database. It is a valid part of an overall response, yet it leaves the technical exposure intact, so it is not the best representation of reducing the risk to an acceptable level in this scenario.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.