Courseiva

CRISC Risk Response and Reporting Practice Question

An organization has decided to purchase cyber insurance to cover potential losses from a ransomware event affecting its order-processing systems. Which risk response has the organization selected?

⚠ Common exam trap

The trap here is treating insurance as mitigation because it feels like a protective measure rather than a financial arrangement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk transfer

Insurance is the classic transfer response: a premium is exchanged for the insurer's assumption of defined financial losses. The operational risk of ransomware remains with the organization, which is why transfer is often paired with mitigation. Avoidance would end the activity, mitigation would reduce likelihood or impact directly, and acceptance would retain the loss without external coverage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk acceptance

    Why it's wrong here

    Acceptance means retaining the risk knowingly without additional action, often because it falls within appetite or the cost of treatment exceeds the benefit. Here the organization is taking a deliberate step to move financial exposure to an insurer, so it is not simply absorbing the loss. Acceptance and transfer differ in whether a third party assumes the consequence.

  • ✗

    Risk mitigation

    Why it's wrong here

    Mitigation reduces the likelihood or impact of a risk through controls such as segmentation, backups, or endpoint protection. Buying insurance does not reduce how often a ransomware event occurs or how much operational disruption it causes; it addresses the financial aftermath. The organization may also mitigate separately, but the described action is purely financial transfer of loss.

  • ✗

    Risk avoidance

    Why it's wrong here

    Avoidance means eliminating the activity or asset that generates the risk, such as shutting down the exposed platform or discontinuing the process. The organization is continuing to operate its order-processing systems while shifting financial consequences to an insurer, so the underlying activity and its exposure remain. Avoidance would remove the risk source entirely rather than compensate for losses.

  • ✓

    Risk transfer

    Why this is correct

    Purchasing insurance shifts the financial consequence of a specified loss to a third party in exchange for a premium. The risk itself still exists and the systems remain exposed, but the monetary impact is contractually borne by the insurer within policy limits and conditions. This is the defining characteristic of transfer as a risk response.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.