hardMultiple Choice
CRISC Practice Question: A risk assessment for a healthcare organization…
A risk assessment for a healthcare organization reveals a high likelihood of data breaches due to weak encryption on portable devices. The organization decides to deploy full-disk encryption and enforce multi-factor authentication. Which risk response strategy is being applied?
⚠ Common exam trap
It's easy for candidates to confuse 'avoidance' with 'mitigation' — avoidance eliminates the risk by discontinuing the activity (e.g., banning portable devices), while mitigation reduces the risk through controls like encryption and MFA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mitigation
Deploying full-disk encryption and multi-factor authentication directly reduces the likelihood and/or impact of data breaches from weak encryption on portable devices. This is the definition of risk mitigation — applying controls to lower risk to an acceptable level. The organization is actively reducing the vulnerability, not transferring, accepting, or avoiding the risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transfer
Why it's wrong here
Transfer shifts financial impact to a third party, typically via cyber insurance or outsourcing; encryption and MFA change the likelihood itself, not who bears the loss. It is tempting because insurance is common in healthcare, and would be correct if a policy or vendor contract covered breach costs.
- ✗
Acceptance
Why it's wrong here
Acceptance acknowledges the risk and takes no mitigating action; deploying full-disk encryption and MFA actively reduces likelihood, so it is not acceptance. It is tempting when residual risk is tolerable, and would be correct if the organisation documented the risk and proceeded unchanged.
- ✗
Avoidance
Why it's wrong here
Avoidance eliminates the activity or asset generating the risk; here the portable devices remain in use, with encryption and MFA applied to reduce likelihood. It is tempting as the strongest response, and would be correct if the organisation ceased storing data on portable devices entirely.
- ✓
Mitigation
Why this is correct
Full-disk encryption and multi-factor authentication directly reduce the likelihood of portable-device breaches, satisfying the stem's high-likelihood constraint. This is mitigation: applying controls to lower inherent risk rather than transferring it via insurance, avoiding it by ceasing the activity, or accepting it unchanged.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.