CRISC Risk Response and Mitigation Practice Question
A risk practitioner at a financial services firm is updating the risk register. For a risk involving unauthorized access to the customer database, the risk owner has decided to purchase a cyber liability insurance policy that covers breach-related costs. Which risk response option has the risk owner selected?
⚠ Common exam trap
Candidates often confuse risk transfer with risk mitigation because both involve taking action, but transfer specifically shifts financial impact to a third party while mitigation reduces the risk itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk transfer
The risk owner chose to purchase insurance, which is a financial arrangement that shifts the potential loss to an insurer. This is a textbook example of risk transfer. The other options do not match because the organization is not eliminating the activity (avoidance), not implementing controls to reduce likelihood or impact (mitigation), and not simply bearing the risk without action (acceptance).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance means acknowledging the risk and choosing to bear the potential loss without taking any action to transfer or mitigate it. In this scenario, the organization is taking action by purchasing insurance, so it is not simply accepting the risk. Acceptance would involve no additional measures and retaining the full financial impact.
- ✗
Risk mitigation
Why it's wrong here
Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. While insurance may seem to reduce impact, it does not reduce the likelihood of unauthorized access, nor does it reduce the actual impact; it only compensates financially after the fact. Mitigation typically refers to preventive or detective controls, not financial compensation mechanisms.
- ✓
Risk transfer
Why this is correct
Purchasing insurance shifts the financial impact of a risk to a third party. This is a classic example of risk transfer, where the organization pays a premium to transfer the potential financial loss. The risk itself (unauthorized access) is not eliminated, but the financial consequences are shared or shifted to the insurer, which is a valid risk response under CRISC.
- ✗
Risk avoidance
Why it's wrong here
Risk avoidance means eliminating the activity that gives rise to the risk altogether. Here, the organization continues to operate the customer database, so it is not avoiding the risk. Avoidance would involve ceasing the collection or storage of customer data, which is not the case in this scenario. Therefore, this option does not describe the chosen response.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.