Courseiva
IT Risk Assessment →mediumMultiple Choice

CRISC IT Risk Assessment Practice Question

An organization decides to outsource its data center operations to a cloud provider with strict contractual penalties for security breaches. This is an example of which risk treatment option?

⚠ Common exam trap

CRISC often tests the distinction between risk transfer and risk mitigation, where candidates incorrectly choose 'mitigate' because contractual penalties seem like a control, but the key is that the financial impact is shifted to a third party.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Transfer

Outsourcing data center operations to a cloud provider with contractual penalties for security breaches shifts the financial impact of a risk event to a third party. This is the definition of risk transfer, where the organization pays another party (via contract, insurance, or outsourcing) to bear the risk. The strict contractual penalties ensure the provider absorbs the cost if a breach occurs, which is the hallmark of transfer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Accept

    Why it's wrong here

    Acceptance retains the risk with no action beyond acknowledging it; this scenario actively shifts breach consequences to the provider through contractual penalties. It tempts when residual risk is tolerable and no treatment is justified, but outsourcing with enforceable penalties is deliberate transfer, not acceptance.

  • ✗

    Avoid

    Why it's wrong here

    Outsourcing transfers the risk to a provider rather than eliminating the activity, so the organisation still depends on data centre operations and retains accountability; avoidance means discontinuing the processing entirely. It tempts because contractual penalties appear to remove exposure, but that is risk transfer, not avoidance.

  • ✗

    Mitigate

    Why it's wrong here

    Mitigate reduces likelihood or impact through controls; transferring risk via contract, penalties and insurance is the correct classification here. Mitigate would apply if the organisation kept the data centre and added safeguards such as segmentation, monitoring or redundancy.

  • ✓

    Transfer

    Why this is correct

    Outsourcing with contractual penalties shifts financial loss from security breaches to the cloud provider. Transfer moves risk to a third party via contract, unlike avoid, mitigate or accept. The penalties clause confirms the loss is borne externally, satisfying the transfer definition.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.