CRISC IT Risk Assessment Practice Question
An organization is considering purchasing cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment option?
⚠ Common exam trap
CRISC often tests the distinction between transfer and mitigate, so the trap is assuming that buying insurance reduces the likelihood or impact of a breach rather than simply shifting financial consequences to a third party.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transfer
Purchasing cyber insurance transfers the financial consequences of a data breach to an insurer in exchange for premiums, which is the definition of risk transfer. The organization retains some residual risk (deductibles, uncovered losses, reputational damage), but the primary treatment mechanism is transfer. This is distinct from mitigation, which reduces likelihood or impact through controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept
Why it's wrong here
Acceptance retains the risk and its financial consequences without any treatment action; purchasing insurance transfers those losses to the insurer for a premium. The organisation is not absorbing the residual impact itself. Acceptance would be correct where no action is taken and the loss is borne internally.
- ✓
Transfer
Why this is correct
Purchasing cyber insurance shifts the financial consequence of a breach to a third party, which is risk transfer. The organisation retains the risk itself but compensates for losses through the insurer, rather than avoiding, mitigating or accepting it.
- ✗
Avoid
Why it's wrong here
Avoidance means eliminating the activity that generates the risk, such as ceasing card handling entirely. Buying cyber insurance transfers the financial consequence to the insurer, so the breach exposure remains. Insurance is the right treatment when the organisation wishes to retain the activity but cap its financial impact.
- ✗
Mitigate
Why it's wrong here
Incorrect; mitigation implements controls.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.