CRISC IT Risk Assessment Practice Question
A risk assessment identifies a threat with high likelihood and high impact. The risk owner proposes transferring the risk via cyber insurance. However, the insurance policy has a high deductible and excludes certain attack types. Which THREE of the following should be considered when evaluating the effectiveness of this risk transfer?
⚠ Common exam trap
CRISC often tests the misconception that buying insurance equals eliminating risk — candidates must recognize that deductibles, exclusions, and premium economics determine the actual effectiveness of the transfer, not the mere existence of a policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The cost of the insurance premium relative to the expected loss
Option C is correct because the premium is the direct cost of transferring the risk, and it must be weighed against the expected loss (likelihood × impact) to determine whether the transfer is economically worthwhile. Option D is correct because insurance rarely eliminates a risk entirely; the high deductible and any uncovered portions leave a residual risk that the organization still owns and must evaluate. Option E is correct because the policy's coverage limits and exclusions define exactly which attack types and loss amounts are actually transferred, directly determining the transfer's effectiveness. Option A is not correct here because operational productivity impact is a factor in assessing the risk itself, not in evaluating whether the insurance transfer works. Option B is likewise not correct because the likelihood of the threat event is an input to the original risk assessment, not a measure of the transfer's effectiveness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The impact of the risk on operational productivity
Why it's wrong here
Operational productivity impact describes the consequence of the risk materialising, not the insurance policy's ability to absorb it; the deductible and exclusions determine residual financial exposure. It is tempting because impact quantification underpins risk analysis, and it would be the right consideration when deciding whether to mitigate or accept the risk.
- ✗
The likelihood of the threat event occurring
Why it's wrong here
Likelihood was already established as high during the risk assessment; re-evaluating it does not test whether the policy's deductible and exclusions leave residual loss. It is tempting because likelihood drives risk scoring, and it would be relevant when prioritising which risks to treat rather than judging a transfer mechanism's coverage.
- ✓
The cost of the insurance premium relative to the expected loss
Why this is correct
Comparing premium against expected loss establishes whether transferring the risk is economically rational. This satisfies the stem's evaluation requirement by testing cost-effectiveness: if premiums approach or exceed probable losses, retention or mitigation may deliver better value than insurance.
- ✓
The residual risk after insurance is applied
Why this is correct
Residual risk quantifies the exposure remaining after insurance payouts, deductibles and exclusions are applied. This satisfies the stem's evaluation requirement by revealing how much high-impact risk stays with the organisation, confirming whether transfer meaningfully reduces risk or merely shifts a portion.
- ✓
The extent of coverage and exclusions in the policy
Why this is correct
Coverage scope and exclusions determine which attack types the policy actually indemnifies; excluded events remain fully retained by the organisation. This satisfies the stem's evaluation requirement by testing whether the transfer genuinely applies to the identified high-likelihood threat rather than leaving it unmitigated.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.