CRISC IT Risk Assessment Practice Question
A risk assessment reveals a high inherent risk that is within the organization's risk appetite. The risk owner documents the risk and formally accepts it. This is an example of which risk treatment option?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accept
When a risk is within appetite, it may be formally accepted with sign-off.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Accept
Why this is correct
Acceptance means acknowledging the risk and choosing to bear it without further treatment, which is valid when inherent risk falls within the organisation's stated risk appetite. The risk owner's documented, formal acceptance satisfies that treatment definition.
- ✗
Mitigate
Why it's wrong here
Mitigate reduces the likelihood or impact of a risk through controls; accepting an unmodified risk within appetite is retention, not mitigation. It is tempting because mitigation is the most common treatment, and would be correct when implementing controls to lower inherent risk to an acceptable level.
- ✗
Transfer
Why it's wrong here
Transfer shifts risk to a third party such as an insurer or outsourcer, but the stem involves no third party and no contractual risk shift — the owner retains it. Transfer would be correct where financial impact is shared or insured, for example purchasing cyber liability cover.
- ✗
Avoid
Why it's wrong here
Avoidance eliminates the activity or process generating the risk entirely, yet the stem shows the risk being retained and formally accepted, not withdrawn. Avoidance would be correct where the risk falls outside appetite and the business activity can be discontinued or redesigned to remove the exposure.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.