Courseiva

CRISC Risk Response and Mitigation Practice Question

A risk practitioner at a financial services firm is updating the risk register. For a risk involving unauthorized access to the customer database, the risk owner has decided to purchase a cyber liability insurance policy that covers breach-related costs. Which risk response option has the risk owner selected?

⚠ Common exam trap

Candidates often confuse risk transfer with risk mitigation because both involve taking action, but transfer specifically shifts financial impact to a third party while mitigation reduces the risk itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk transfer

The risk owner chose to purchase insurance, which is a financial arrangement that shifts the potential loss to an insurer. This is a textbook example of risk transfer. The other options do not match because the organization is not eliminating the activity (avoidance), not implementing controls to reduce likelihood or impact (mitigation), and not simply bearing the risk without action (acceptance).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk acceptance

    Why it's wrong here

    Risk acceptance means acknowledging the risk and choosing to bear the potential loss without taking any action to transfer or mitigate it. In this scenario, the organization is taking action by purchasing insurance, so it is not simply accepting the risk. Acceptance would involve no additional measures and retaining the full financial impact.

  • ✗

    Risk mitigation

    Why it's wrong here

    Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. While insurance may seem to reduce impact, it does not reduce the likelihood of unauthorized access, nor does it reduce the actual impact; it only compensates financially after the fact. Mitigation typically refers to preventive or detective controls, not financial compensation mechanisms.

  • ✓

    Risk transfer

    Why this is correct

    Purchasing insurance shifts the financial impact of a risk to a third party. This is a classic example of risk transfer, where the organization pays a premium to transfer the potential financial loss. The risk itself (unauthorized access) is not eliminated, but the financial consequences are shared or shifted to the insurer, which is a valid risk response under CRISC.

  • ✗

    Risk avoidance

    Why it's wrong here

    Risk avoidance means eliminating the activity that gives rise to the risk altogether. Here, the organization continues to operate the customer database, so it is not avoiding the risk. Avoidance would involve ceasing the collection or storage of customer data, which is not the case in this scenario. Therefore, this option does not describe the chosen response.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.