Courseiva
Risk Response and MitigationhardMultiple ChoiceObjective-mapped

CRISC Risk Response and Mitigation Practice Question

An organization is considering outsourcing its IT support to a third-party provider. The risk manager has identified that the provider's data handling practices may not comply with regulatory requirements. Which of the following is the BEST risk response strategy?

⚠ Common exam trap

Watch out — candidates often choose 'mitigate by monitoring' or 'transfer through contract' because they seem proactive, but CRISC expects you to recognize that regulatory compliance risk cannot be effectively transferred or monitored away when the provider's practices are fundamentally non-compliant.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Avoid by keeping IT support in-house

The risk manager has identified that the provider's data handling practices may not comply with regulatory requirements, which represents a high-severity compliance risk that cannot be effectively mitigated through monitoring alone. Avoiding the risk by keeping IT support in-house eliminates the exposure entirely, making it the best response when the risk level exceeds the organization's risk appetite and cannot be reduced to an acceptable level through other strategies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Mitigate by regularly monitoring the provider

    Why it's wrong here

    Monitoring is good but may not fully address regulatory risk.

  • Avoid by keeping IT support in-house

    Why this is correct

    Avoidance is appropriate when compliance cannot be assured.

  • Transfer the risk through the outsourcing contract

    Why it's wrong here

    Contract alone may not ensure compliance.

  • Accept the risk because the provider is cheaper

    Why it's wrong here

    Accepting regulatory risk is not advisable.

About these practice questions

One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.