Courseiva
IT Risk Assessment →hardMultiple Select

CRISC IT Risk Assessment Practice Question

A risk assessment identifies a threat with high likelihood and high impact. The risk owner proposes transferring the risk via cyber insurance. However, the insurance policy has a high deductible and excludes certain attack types. Which THREE of the following should be considered when evaluating the effectiveness of this risk transfer?

⚠ Common exam trap

CRISC often tests the misconception that buying insurance equals eliminating risk — candidates must recognize that deductibles, exclusions, and premium economics determine the actual effectiveness of the transfer, not the mere existence of a policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The cost of the insurance premium relative to the expected loss

Option C is correct because the premium is the direct cost of transferring the risk, and it must be weighed against the expected loss (likelihood × impact) to determine whether the transfer is economically worthwhile. Option D is correct because insurance rarely eliminates a risk entirely; the high deductible and any uncovered portions leave a residual risk that the organization still owns and must evaluate. Option E is correct because the policy's coverage limits and exclusions define exactly which attack types and loss amounts are actually transferred, directly determining the transfer's effectiveness. Option A is not correct here because operational productivity impact is a factor in assessing the risk itself, not in evaluating whether the insurance transfer works. Option B is likewise not correct because the likelihood of the threat event is an input to the original risk assessment, not a measure of the transfer's effectiveness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The impact of the risk on operational productivity

    Why it's wrong here

    Operational productivity impact describes the consequence of the risk materialising, not the insurance policy's ability to absorb it; the deductible and exclusions determine residual financial exposure. It is tempting because impact quantification underpins risk analysis, and it would be the right consideration when deciding whether to mitigate or accept the risk.

  • ✗

    The likelihood of the threat event occurring

    Why it's wrong here

    Likelihood was already established as high during the risk assessment; re-evaluating it does not test whether the policy's deductible and exclusions leave residual loss. It is tempting because likelihood drives risk scoring, and it would be relevant when prioritising which risks to treat rather than judging a transfer mechanism's coverage.

  • ✓

    The cost of the insurance premium relative to the expected loss

    Why this is correct

    Comparing premium against expected loss establishes whether transferring the risk is economically rational. This satisfies the stem's evaluation requirement by testing cost-effectiveness: if premiums approach or exceed probable losses, retention or mitigation may deliver better value than insurance.

  • ✓

    The residual risk after insurance is applied

    Why this is correct

    Residual risk quantifies the exposure remaining after insurance payouts, deductibles and exclusions are applied. This satisfies the stem's evaluation requirement by revealing how much high-impact risk stays with the organisation, confirming whether transfer meaningfully reduces risk or merely shifts a portion.

  • ✓

    The extent of coverage and exclusions in the policy

    Why this is correct

    Coverage scope and exclusions determine which attack types the policy actually indemnifies; excluded events remain fully retained by the organisation. This satisfies the stem's evaluation requirement by testing whether the transfer genuinely applies to the identified high-likelihood threat rather than leaving it unmitigated.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.