Courseiva
hardMultiple Choice

CRISC Practice Question: A risk assessment for a healthcare organization…

A risk assessment for a healthcare organization reveals a high likelihood of data breaches due to weak encryption on portable devices. The organization decides to deploy full-disk encryption and enforce multi-factor authentication. Which risk response strategy is being applied?

⚠ Common exam trap

It's easy for candidates to confuse 'avoidance' with 'mitigation' — avoidance eliminates the risk by discontinuing the activity (e.g., banning portable devices), while mitigation reduces the risk through controls like encryption and MFA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mitigation

Deploying full-disk encryption and multi-factor authentication directly reduces the likelihood and/or impact of data breaches from weak encryption on portable devices. This is the definition of risk mitigation — applying controls to lower risk to an acceptable level. The organization is actively reducing the vulnerability, not transferring, accepting, or avoiding the risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Transfer

    Why it's wrong here

    Transfer shifts financial impact to a third party, typically via cyber insurance or outsourcing; encryption and MFA change the likelihood itself, not who bears the loss. It is tempting because insurance is common in healthcare, and would be correct if a policy or vendor contract covered breach costs.

  • ✗

    Acceptance

    Why it's wrong here

    Acceptance acknowledges the risk and takes no mitigating action; deploying full-disk encryption and MFA actively reduces likelihood, so it is not acceptance. It is tempting when residual risk is tolerable, and would be correct if the organisation documented the risk and proceeded unchanged.

  • ✗

    Avoidance

    Why it's wrong here

    Avoidance eliminates the activity or asset generating the risk; here the portable devices remain in use, with encryption and MFA applied to reduce likelihood. It is tempting as the strongest response, and would be correct if the organisation ceased storing data on portable devices entirely.

  • ✓

    Mitigation

    Why this is correct

    Full-disk encryption and multi-factor authentication directly reduce the likelihood of portable-device breaches, satisfying the stem's high-likelihood constraint. This is mitigation: applying controls to lower inherent risk rather than transferring it via insurance, avoiding it by ceasing the activity, or accepting it unchanged.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.