Courseiva

CRISC Risk Response and Mitigation Practice Question

An organization's security team recommends implementing a web application firewall (WAF) to protect against SQL injection attacks. The risk manager evaluates the cost of the WAF and the likelihood of a successful attack. This evaluation is BEST described as:

⚠ Common exam trap

Many exam-takers confuse the evaluation of a control's cost against risk reduction with inherent risk assessment, but inherent risk is calculated without any controls in place, whereas this scenario explicitly involves weighing the cost of a specific control against the risk it mitigates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cost-benefit analysis

The risk manager is comparing the cost of implementing the WAF against the likelihood and potential impact of a SQL injection attack. This direct comparison of mitigation cost to risk reduction benefit is the essence of a cost-benefit analysis, which determines whether the control is economically justified. It is not a calculation of residual or inherent risk, nor is it an acceptance decision.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Residual risk calculation

    Why it's wrong here

    Residual risk is the exposure remaining after controls are implemented and verified, not the cost-versus-likelihood comparison of a proposed control. The stem describes evaluating whether to adopt a WAF, which is risk response analysis. Residual calculation would be correct after the WAF is deployed and its effectiveness measured.

  • ✗

    Inherent risk assessment

    Why it's wrong here

    Inherent risk is assessed before any controls exist, so it excludes the WAF's mitigating effect entirely. The stem already factors in the proposed control's cost and the post-control attack likelihood, which is residual risk. Inherent assessment would be correct when evaluating exposure in the absence of any safeguards.

  • ✓

    Cost-benefit analysis

    Why this is correct

    Cost-benefit analysis weighs the WAF's implementation cost against the reduced likelihood and impact of a successful SQL injection attack, which is exactly the comparison described. Control selection and risk assessment lack the explicit monetary trade-off, while residual risk evaluation occurs after treatment.

  • ✗

    Risk acceptance

    Why it's wrong here

    Risk acceptance means knowingly retaining a risk without further treatment; here the manager is weighing WAF cost against attack likelihood, which is cost-benefit analysis feeding a treatment decision, not acceptance. Acceptance is tempting because the WAF may ultimately be declined, and it would be correct only once that decision to retain the risk is formally made.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.