CRISC Risk Response and Reporting Practice Question
An organization's risk register lists a ransomware exposure against its primary order-processing system. The chief information security officer decides to purchase cyber insurance that covers ransomware losses up to $10 million. Which risk response has been selected?
⚠ Common exam trap
The trap here is assuming that any action taken against a risk counts as mitigation, when shifting the financial consequence is specifically transfer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk transfer
Risk transfer shifts the financial impact of a risk to another party, most commonly through insurance or contractual indemnification. Purchasing a cyber insurance policy leaves the ransomware threat and the system unchanged while moving the monetary consequence to the insurer. Because deductibles, exclusions, and coverage caps remain the organization's burden, the residual risk must still be recorded and accepted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Risk transfer
Why this is correct
Purchasing cyber insurance shifts the financial consequence of ransomware losses to the insurer in exchange for a premium, which is the defining characteristic of risk transfer. The threat still exists and the system keeps operating, but the economic burden of a covered event moves to a third party. Transferring risk does not eliminate it, so residual exposure such as deductibles and uncovered amounts must still be tracked and accepted.
- ✗
Risk avoidance
Why it's wrong here
Avoidance means eliminating the activity that creates the risk, for example decommissioning the order-processing system or refusing to accept online orders. The organization here continues operating the system and simply insures the loss, so the underlying risk-generating activity remains fully in place. Avoidance would remove the exposure entirely, which is clearly not what purchasing a policy accomplishes.
- ✗
Risk acceptance
Why it's wrong here
Acceptance means acknowledging the risk and retaining it without taking action to change likelihood, impact, or financial responsibility. By buying a policy, the organization has deliberately taken action to move the financial burden elsewhere, so this is not passive retention. Acceptance is the appropriate label only when no treatment is applied and the risk owner formally agrees to bear the exposure.
- ✗
Risk mitigation
Why it's wrong here
Mitigation reduces the likelihood or impact of a threat through controls such as segmentation, endpoint protection, or offline backups. Buying insurance does not change the probability that ransomware strikes or the technical damage it causes; it changes who bears the financial consequence. This scenario describes transferring the financial exposure to a third party, not reducing the exposure itself through preventive or detective controls.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.