CRISC IT Risk Assessment Practice Question
An organization decides to outsource its data center operations to a cloud provider with strict contractual penalties for security breaches. This is an example of which risk treatment option?
⚠ Common exam trap
CRISC often tests the distinction between risk transfer and risk mitigation, where candidates incorrectly choose 'mitigate' because contractual penalties seem like a control, but the key is that the financial impact is shifted to a third party.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transfer
Outsourcing data center operations to a cloud provider with contractual penalties for security breaches shifts the financial impact of a risk event to a third party. This is the definition of risk transfer, where the organization pays another party (via contract, insurance, or outsourcing) to bear the risk. The strict contractual penalties ensure the provider absorbs the cost if a breach occurs, which is the hallmark of transfer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept
Why it's wrong here
Acceptance retains the risk with no action beyond acknowledging it; this scenario actively shifts breach consequences to the provider through contractual penalties. It tempts when residual risk is tolerable and no treatment is justified, but outsourcing with enforceable penalties is deliberate transfer, not acceptance.
- ✗
Avoid
Why it's wrong here
Outsourcing transfers the risk to a provider rather than eliminating the activity, so the organisation still depends on data centre operations and retains accountability; avoidance means discontinuing the processing entirely. It tempts because contractual penalties appear to remove exposure, but that is risk transfer, not avoidance.
- ✗
Mitigate
Why it's wrong here
Mitigate reduces likelihood or impact through controls; transferring risk via contract, penalties and insurance is the correct classification here. Mitigate would apply if the organisation kept the data centre and added safeguards such as segmentation, monitoring or redundancy.
- ✓
Transfer
Why this is correct
Outsourcing with contractual penalties shifts financial loss from security breaches to the cloud provider. Transfer moves risk to a third party via contract, unlike avoid, mitigate or accept. The penalties clause confirms the loss is borne externally, satisfying the transfer definition.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.