CRISC Risk Response and Mitigation Practice Question
A risk assessment identifies that a legacy system has a high risk of failure with no available vendor support. The organization decides to decommission the system and migrate to a modern platform. This is:
⚠ Common exam trap
Test-takers frequently confuse risk avoidance with risk mitigation, mistakenly thinking that any proactive action (like migrating) is a form of mitigation, whereas avoidance specifically means ceasing the activity that generates the risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk Avoidance
Decommissioning the legacy system and migrating to a modern platform eliminates the risk entirely by removing the vulnerable asset from the environment. This is the definition of risk avoidance, as the organization chooses not to engage with the risk at all rather than reducing or transferring it. The decision directly addresses the high risk of failure and lack of vendor support by removing the system from operation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Risk Avoidance
Why this is correct
Decommissioning the legacy system eliminates the risk entirely by removing the asset and its exposure, rather than transferring, mitigating or accepting it. Eliminating the activity that generates the risk is the defining characteristic of risk avoidance.
- ✗
Risk Transfer
Why it's wrong here
Transfer shifts the financial consequence to a third party, typically through insurance or contractual indemnity, and does not remove the legacy system's failure risk. It is tempting because migrating to a vendor-hosted modern platform can involve contractual arrangements, but the decision described is to eliminate the system, not outsource its risk.
- ✗
Risk Mitigation
Why it's wrong here
Mitigation reduces the likelihood or impact of a risk while retaining the underlying asset or activity; decommissioning and migrating removes the legacy system and its exposure altogether, which is risk avoidance. Mitigation is tempting because it is the broadest treatment category and often involves corrective action on existing systems.
- ✗
Risk Acceptance
Why it's wrong here
Acceptance means acknowledging the risk and taking no action to reduce it, whereas decommissioning and migrating eliminates the exposure entirely. It is tempting because acceptance is valid when the cost of treatment exceeds the potential loss, or when the risk falls within the organisation's stated tolerance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.