Courseiva
IT Risk Identification →hardMultiple Choice

CRISC IT Risk Identification Practice Question

A risk practitioner is evaluating the risk that a cloud provider's regional outage disrupts a company's order management system. The company has a recovery time objective (RTO) of four hours, but the provider's documented regional recovery capability is estimated at twelve hours. Which of the following BEST characterizes the risk exposure this gap represents?

⚠ Common exam trap

The trap here is treating the gap as an inherent, uncontrollable cloud risk, when the company can still reduce impact through architecture, contracts, and contingency planning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A residual risk that exceeds the company's risk appetite for this process.

The four-hour recovery objective against a twelve-hour provider capability means the remaining exposure after current arrangements exceeds what the company is willing to tolerate. That is residual risk above appetite, and it should drive treatment decisions such as multi-region architecture, alternate recovery arrangements, or renegotiated service levels rather than being accepted or dismissed as inherent.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A control deficiency in the provider's disaster recovery testing program.

    Why it's wrong here

    The gap reflects a mismatch between the company's recovery requirement and the provider's demonstrated capability, not necessarily a testing deficiency. The provider may test adequately yet still deliver a twelve-hour recovery. Framing this as a testing problem misdirects remediation toward audits and test reviews instead of addressing the mismatch through architecture, contract terms, or alternate recovery arrangements.

  • ✗

    An inherent risk that cannot be mitigated through any contractual arrangement.

    Why it's wrong here

    Cloud concentration risk is real, but it is not immune to mitigation. Contracts can specify recovery commitments, credits, and notification duties, and architecture can add multi-region or multi-provider resilience. Declaring the exposure unmitigable would discourage the very actions that reduce impact, such as failing over to a secondary region or negotiating stronger service levels with the provider.

  • ✗

    A risk that should be accepted because cloud outages are outside the company's control.

    Why it's wrong here

    Acceptance is a valid treatment only when the exposure falls within appetite and treatment would cost more than the benefit. Here the outage window exceeds the recovery objective, so accepting it would expose the business to prolonged order processing disruption. Control is not absolute, but the company can still influence impact through architecture, contracts, and contingency planning, so acceptance is premature.

  • ✓

    A residual risk that exceeds the company's risk appetite for this process.

    Why this is correct

    The company requires recovery within four hours, but the provider's capability implies up to twelve hours of downtime, so the residual exposure after existing arrangements exceeds the stated tolerance. That gap is a residual risk above appetite, which should trigger treatment options such as multi-region design, alternate providers, or revised recovery objectives. It is the clearest characterization of the exposure described.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.