CRISC Risk Response and Mitigation Practice Question
A risk assessment reveals that a legacy system has a high likelihood of failure. The system is critical and cannot be replaced immediately. The company decides to implement manual overrides and additional monitoring. This is an example of:
⚠ Common exam trap
It's easy for candidates to confuse 'risk mitigation' with 'risk acceptance' because the system is still running with known vulnerabilities, but the key differentiator is that active controls are being applied to reduce the risk, not merely acknowledged.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk Mitigation
Implementing manual overrides and additional monitoring reduces the probability or impact of the legacy system failure without eliminating the risk entirely. This is the definition of risk mitigation, as it applies controls to lower the residual risk to an acceptable level while the system remains in operation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk Transfer
Why it's wrong here
Transfer requires shifting the financial consequence to a third party, typically via insurance or a contractual clause. Manual overrides and monitoring retain the risk internally and instead reduce its likelihood and impact, so no counterparty absorbs anything here.
- ✓
Risk Mitigation
Why this is correct
Manual overrides and added monitoring reduce the likelihood or impact of the legacy system's failure while it remains in service, which is risk mitigation. The system cannot be replaced immediately, so avoidance and acceptance are ruled out; the controls lower the high likelihood identified in the assessment.
- ✗
Risk Acceptance
Why it's wrong here
Manual overrides and monitoring reduce impact and likelihood while the legacy system remains in use, which is risk mitigation, not acceptance. Acceptance means acknowledging the risk and taking no action beyond documenting it, which would be the choice if the system were non-critical or replacement were already funded.
- ✗
Risk Avoidance
Why it's wrong here
Risk avoidance eliminates the activity or system generating the risk; here the legacy system remains in service with added controls, so the risk is retained and reduced. It is tempting because manual overrides sound like removing exposure, but that is mitigation. Avoidance would mean decommissioning the system.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.