Courseiva

CRISC · domain

Risk Response and Mitigation

This domain covers selecting, implementing, and validating risk responses—mitigation, transfer, avoidance, and acceptance—and tracking residual risk against appetite. Questions test sequencing control implementation, classifying response types, and judging whether proceeding above appetite with monitoring is acceptable. Expect scenario-based items tied to risk register updates and control ownership.

94 questions23 easy39 medium32 hard

Focused practice

Practice Risk Response and Mitigation questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Risk Response and Mitigation

Be able to pick the correct risk response for a scenario, order treatment steps, and classify controls. The key is recognizing that residual risk above appetite requires explicit acceptance by the accountable owner, not silent continuation.

Classifying responses as mitigate, transfer, avoid, or accept for a given scenario

Sequencing risk treatment steps: assess, select response, implement controls, monitor residual risk

Distinguishing preventive, detective, and corrective controls and their placement in the process

Determining whether residual risk above appetite can proceed with monitoring and approval

Watch out for

Common Risk Response and Mitigation exam traps

  • ▸Treating risk acceptance as a failure of response rather than a valid, documented decision with owner sign-off
  • ▸Confusing risk transfer (insurance, contracts) with risk mitigation, which reduces likelihood or impact directly
  • ▸Skipping control effectiveness testing and assuming implementation equals reduced residual risk

Question index

All Risk Response and Mitigation questions (94)

Click any question to see the full explanation, or start a practice session above.

1

A risk assessment reveals that the cost of implementing a control ($500k) exceeds the annualized loss expectancy (ALE) of $300k. The risk is currently within the organization's risk appetite. What is the appropriate risk response?

Medium
2

A small retail company has determined that the risk of a point-of-sale (POS) system malware infection is high. The company decides to implement a whitelisting solution that only allows approved applications to run on POS terminals. This is an example of which risk response?

Easy
3

A company has identified a critical vulnerability in a legacy application that cannot be patched immediately. The application is used by a small number of users and supports a non-critical business process. Which of the following is the MOST appropriate risk response strategy?

Easy
4

After implementing a set of controls, the risk owner calculates the residual risk and finds it is still above the risk tolerance. However, the cost to further reduce the risk exceeds the potential loss. What is the MOST appropriate next step?

Medium
5

An organization's security team recommends implementing a web application firewall (WAF) to protect against SQL injection attacks. The risk manager evaluates the cost of the WAF and the likelihood of a successful attack. This evaluation is BEST described as:

Medium
6

A company has implemented a risk mitigation plan that includes technical controls. However, six months later, the residual risk is still higher than expected. The risk practitioner suspects that the controls are not being followed. Which of the following is the BEST approach to verify this?

Hard
7

A software company has identified that a critical third-party library used in its product has a known remote code execution vulnerability. The vendor has not released a patch, and the product is used by customers who cannot accept downtime. The risk practitioner recommends isolating the library's functionality in a sandboxed process with restricted permissions. Which risk response strategy does this represent?

Medium
8

A hospital's risk team has documented that its infusion pump fleet runs an unsupported operating system, creating a high risk of compromise. Replacing the pumps requires capital approval that will take 18 months, and the pumps cannot be taken offline in the interim. Which risk response is MOST appropriate for the risk practitioner to recommend?

Medium
9

A security team identifies a critical vulnerability in a web application that cannot be patched immediately. They deploy a web application firewall (WAF) to block exploitation attempts. This is an example of:

Easy
10

Based on the risk register exhibit, which of the following is the MOST appropriate risk response for R-0042?

Hard
11

A global manufacturing company is implementing a new ERP system across multiple regions. The project manager has identified a risk that data migration from legacy systems may cause data corruption, leading to production delays. The risk owner proposes conducting a full data reconciliation after migration. However, the IT director argues that this would be too time-consuming and suggests only sampling data for verification. The risk manager must decide on the risk response. The project timeline is tight, and the company has a low tolerance for data integrity issues. Which of the following is the BEST course of action?

Easy
12

A company has a critical production system with a known vulnerability. Due to the system's age, the vendor no longer supports it. The company decides to implement network segmentation and purchase cyber insurance to cover potential losses. Which TWO risk response options are they applying?

Medium
13

After implementing security controls, a risk assessment shows a residual risk of data exfiltration with a probability of 5% and potential loss of $10 million. The organization's risk appetite allows a maximum acceptable risk level of 3% probability for such impact. The cost of further mitigation is $1 million. What is the best risk response?

Hard
14

A software development company uses a third-party cloud provider to host its source code repositories. The risk practitioner discovers that the provider's contract does not include a right-to-audit clause. The provider has a strong security reputation but is unwilling to add the clause. The company's risk appetite for third-party risk is low. Which action should the risk practitioner recommend FIRST?

Hard
15

A multinational corporation is implementing a risk treatment plan for a critical vendor that has poor security controls. The risk practitioner has recommended contract renegotiation to include security requirements, but the vendor refuses. The business unit insists on continuing the relationship due to cost savings. The risk practitioner's next step should be to:

Hard
16

A risk practitioner at a financial services firm is updating the risk register. For a risk involving unauthorized access to the customer database, the risk owner has decided to purchase a cyber liability insurance policy that covers breach-related costs. Which risk response option has the risk owner selected?

Medium
17

A risk assessment reveals that a data center is located in a flood-prone area. The organization decides to build a secondary data center in a different region and replicate critical data between both sites. This is an example of which risk response?

Easy
18

A multinational corporation is deploying a new IoT-based inventory management system across its warehouses. The risk practitioner identifies that the IoT devices use default administrative credentials and unencrypted communication protocols. The vendor states that a firmware update to address these issues will not be available for six months. The business cannot delay the deployment due to competitive pressures. Which risk response strategy is MOST appropriate in this situation?

Hard
19

A retail company has identified that its point-of-sale (POS) terminals are running an outdated operating system that no longer receives security patches. The risk practitioner recommends upgrading the terminals to a supported OS. The cost of the upgrade is $500,000, while the estimated annual loss from a potential breach is $2,000,000 with a 30% likelihood. Which risk response strategy is being recommended?

Easy
20

A healthcare organization is required by law to retain patient records for seven years. The IT department proposes storing backups on tapes that are kept in an on-site vault. The risk manager notes that the on-site vault is in a flood zone. Which risk response strategy is being applied if the organization decides to move the tapes to a secure off-site facility in a different geographic region?

Easy
21

A financial services firm operates a high-volume transaction processing platform. During a risk assessment, the risk owner determines that the residual risk of database corruption exceeds the risk appetite. The database vendor offers a patch that reduces the vulnerability but requires a 12-hour outage. Business stakeholders refuse the outage. The risk practitioner is asked to recommend a risk response that aligns with the risk appetite without disrupting operations. Which of the following is the BEST recommendation?

Hard
22

A multinational corporation has adopted a risk mitigation strategy for its key suppliers by requiring them to maintain ISO 27001 certification. During an audit, the risk manager discovers that one critical supplier lost its certification six months ago but did not report it, as contractually required. The supplier still has adequate security controls in place, and the relationship is strategically important. The CEO wants to avoid contract termination. What is the MOST appropriate risk response?

Medium
23

A financial services firm has a risk register entry for a core banking application with an inherent risk score of 9 (high). The risk owner implements a new database activity monitoring tool and role-based access reviews. After implementation, the residual risk score is reassessed at 6 (medium). The risk owner now wants to formally document that the risk has been reduced to an acceptable level. Which action should the risk practitioner recommend NEXT?

Medium
24

A multinational corporation has a risk register entry for a potential data breach of customer information. The risk owner has decided to purchase cyber insurance to cover financial losses from a breach. Which of the following BEST describes the residual risk after this risk response?

Hard
25

A risk practitioner is working with the IT team to design controls for a new cloud-based human resources system. The team proposes using encryption for data at rest and in transit, role-based access controls, and regular backups. The risk practitioner notes that these controls address confidentiality, integrity, and availability. Which of the following should the risk practitioner recommend to ensure the controls remain effective over time?

Hard
26

A third-party vendor's security assessment reveals multiple high-risk findings related to data handling. The vendor is unwilling to remediate, citing cost. The vendor contract includes a clause that requires adherence to security standards. The organization's risk appetite for third-party risk is low. What is the most appropriate risk response?

Hard
27

A financial services firm is deploying a new trading platform. The risk committee has approved a risk treatment plan that includes a requirement to implement a circuit breaker that halts trading if losses exceed a predefined threshold. The project manager asks the risk practitioner to verify that the control is designed effectively before go-live. Which activity BEST validates the design of this risk mitigation control?

Hard
28

During a risk assessment, the risk owner identifies that the residual risk level is higher than the risk appetite. Which of the following actions should the risk owner take FIRST?

Easy
29

Which TWO of the following are examples of risk mitigation controls?

Easy
30

An organization uses a legacy system that cannot be patched because the vendor is defunct. The system supports a core business function. The risk assessment shows a high likelihood of exploitation and high impact. The board has decided to keep the system operational due to its criticality. Which risk response should the risk manager recommend?

Hard
31

A risk practitioner is reviewing the organization's risk response strategies for a high-value asset. Which TWO of the following are examples of risk mitigation techniques? (Choose two.)

Easy
32

Order the steps for implementing a risk treatment plan.

Medium
33

A software development company is adopting a DevOps model and wants to accelerate deployments. The risk manager is concerned that rapid changes could introduce security vulnerabilities. The team proposes implementing automated security testing in the CI/CD pipeline. Which of the following BEST describes the risk response strategy being applied?

Medium
34

A multinational bank has a risk appetite that allows for a maximum of 5% downtime for its online banking platform per quarter. The platform currently experiences 8% downtime due to frequent distributed denial-of-service (DDoS) attacks. The risk owner proposes investing in a cloud-based DDoS mitigation service. Which of the following should be the risk practitioner's PRIMARY consideration when evaluating this proposed risk response?

Hard
35

A hospital's risk register identifies that a critical medical imaging server runs an unsupported operating system, creating a high likelihood of exploitation. The vendor will not release a patch, and the server cannot be taken offline because it supports active patient care. The CISO asks the risk practitioner to reduce the likelihood of exploitation without disrupting imaging services. Which risk response is MOST appropriate?

Medium
36

A healthcare organization has identified that its patient portal has a vulnerability that could expose sensitive data. The risk owner decides to implement multifactor authentication (MFA) for all users. After implementation, the risk practitioner conducts a follow-up assessment and finds that some users are sharing credentials, potentially bypassing MFA. The risk practitioner should FIRST:

Medium
37

A financial services firm's risk register shows that a critical trading application has a high inherent risk of unauthorized access. The risk owner decides to implement multifactor authentication (MFA) and role-based access controls (RBAC). After implementation, the residual risk score decreases but remains above the risk appetite. Which of the following should the risk practitioner recommend NEXT?

Medium
38

A bank implements a new transaction monitoring system to detect fraudulent activities. After six months, the system has a high false positive rate, causing analysts to miss real threats. Which of the following is the BEST way to address this risk?

Medium
39

During a review, a risk practitioner discovers that a key control for a high-risk process is not operating effectively. The risk owner is reluctant to invest in additional controls due to budget constraints. What should the risk practitioner do FIRST?

Medium
40

Match each risk response strategy to its definition.

Medium
41

After implementing a new web application, the risk owner reports that the residual risk level is still above the risk appetite. Which of the following should be the risk practitioner's FIRST action?

Medium
42

A multinational corporation is deploying a new enterprise resource planning (ERP) system across 30 countries. The risk manager identifies that data residency laws in several countries require customer data to remain within national borders. The project team proposes using a single global cloud region for simplicity. Which risk response strategy is MOST appropriate for the risk manager to recommend?

Hard
43

A retail company has a risk register that includes a risk of inventory shrinkage due to employee theft. The risk manager decides to implement a new surveillance system and conduct background checks on all new hires. Which risk response strategy is being applied?

Easy
44

An employee with access to sensitive financial data has been observed accessing systems outside of normal working hours and exhibiting erratic behavior. The IT risk manager suspects insider threat. What is the most appropriate risk response?

Medium
45

A financial services company's risk register shows that a critical vulnerability in its online banking application has a high likelihood of exploitation and a high impact. The risk owner decides to implement a web application firewall (WAF) and conduct monthly penetration tests. Which risk response strategy is being applied?

Medium
46

Which TWO of the following are examples of risk avoidance? (Select TWO.)

Medium
47

A risk practitioner is reviewing the organization's risk register and notes that a critical web application has a high inherent risk of SQL injection. The development team proposes implementing a web application firewall (WAF) with virtual patching. The risk practitioner's primary responsibility in this scenario is to:

Medium
48

An organization decides to outsource its data center operations to a third party. This is an example of which risk response?

Easy
49

A risk practitioner is reviewing the organization's risk response plan for a database containing personally identifiable information (PII). The plan states that the database will be encrypted at rest, access will be restricted to authorized personnel, and regular backups will be performed. Which risk response strategy is being applied?

Easy
50

A financial services firm has a critical web application that must remain available 24/7. The risk assessment indicates that a distributed denial-of-service (DDoS) attack could cause significant downtime. The risk owner decides to implement a cloud-based DDoS mitigation service that scrubs traffic before it reaches the application. Which risk response strategy does this represent?

Medium
51

A financial services firm has identified that its primary data center is located in a region prone to hurricanes. The risk manager proposes purchasing business interruption insurance to cover potential losses from a catastrophic event. Which risk response strategy does this represent?

Medium
52

A risk manager is reviewing the organization's risk treatment plan for a critical web application. The plan includes implementing a web application firewall (WAF), conducting regular penetration tests, and purchasing cyber insurance. The risk manager notes that the residual risk after these treatments is still above the risk appetite. According to CRISC, what should the risk manager do NEXT?

Hard
53

An organization has a policy requiring all sensitive data to be encrypted at rest. During an audit, it is found that encryption keys are stored in plaintext on the same server. Which risk response is MOST appropriate?

Medium
54

Sequence the steps for implementing a new control based on risk assessment findings.

Medium
55

Based on the exhibit, which risk is most likely present and what is the most appropriate risk response?

Hard
56

A retail company is launching a new mobile payment application. The risk practitioner is identifying risk response options for the risk of payment fraud. Which TWO of the following are examples of risk mitigation controls? (Choose two.)

Medium
57

A company faces a risk of data loss due to untrained staff. They implement mandatory training and quarterly phishing simulations. This is:

Hard
58

A multinational corporation has a risk register entry for a supplier that provides critical components. The supplier has a history of financial instability, and the risk of supply chain disruption is high. The risk owner decides to dual-source the components from a second supplier. Which risk response strategy does this represent, and what is the primary benefit?

Hard
59

For a risk with very low likelihood and low impact, what is the typical risk response?

Easy
60

A software development company is launching a new mobile application that will collect user location data. The risk manager identifies that the data collection could violate privacy regulations if not properly disclosed. The legal team recommends updating the privacy policy and obtaining explicit user consent. Which risk response strategy is this?

Medium
61

A global company uses a critical third-party vendor for data processing. The inherent risk is high, but the vendor has implemented robust controls. However, due to recent geopolitical instability, the vendor's physical location is at risk. The risk owner recommends purchasing a business continuity insurance policy. Which risk response is being applied?

Medium
62

Which THREE of the following are examples of risk mitigation controls? (Select THREE.)

Easy
63

You are a risk practitioner at a financial institution that is migrating its core banking system to a cloud provider. The migration plan includes a phased approach, with the first phase moving non-critical applications. However, during the second phase (moving customer-facing applications), the cloud provider experiences a major outage that lasts 6 hours. The outage was caused by a misconfiguration in the provider's network. The institution had conducted a risk assessment and identified cloud provider downtime as a risk, but the treatment plan only included a service level agreement (SLA) with financial penalties. The SLA does not cover the reputational damage and loss of customer trust. The risk register shows that the residual risk level was marked as 'low' before the incident. After the incident, senior management is demanding a review. Which of the following is the MOST appropriate action for the risk practitioner to take?

Hard
64

A multinational corporation is developing a risk treatment plan for a newly identified risk: a critical vendor's financial instability could disrupt the supply chain. The risk manager is considering several options. Which TWO of the following are examples of risk mitigation controls that directly reduce the likelihood or impact of this risk? (Choose two.)

Hard
65

A retail company is implementing a new point-of-sale (POS) system that accepts contactless payments. The risk practitioner identifies that the existing network segmentation between the POS environment and the corporate network is inadequate. The risk committee asks for compensating controls that will reduce the risk of lateral movement from a compromised POS terminal. Which TWO of the following controls BEST address this risk? (Choose two.)

Medium
66

A financial services firm has a risk register entry for a critical trading application. The business owner proposes adding a redundant data center to reduce downtime risk. The risk practitioner notes that the redundancy will cost $2 million annually and reduce expected annual loss from $3 million to $500,000. Which factor is MOST important for the risk practitioner to evaluate before recommending approval?

Hard
67

A financial institution is implementing a new online banking platform. The risk assessment identified that the platform will handle sensitive customer data and must comply with GDPR and local banking regulations. The project team proposes encrypting all data at rest and in transit, implementing multi-factor authentication (MFA), and conducting quarterly penetration tests. However, the risk owner is concerned about the residual risk of a sophisticated phishing attack that could bypass MFA. The board has a low risk appetite. What is the BEST way to address this residual risk?

Hard
68

A new privacy regulation requires that all personal data be encrypted at rest. The current systems lack encryption. The cost to implement encryption is moderate, and the risk of non-compliance is high. Which risk response is most appropriate?

Easy
69

A retail company's risk register shows that a point-of-sale system vulnerability has a high likelihood and high impact. The IT team proposes applying a vendor patch, but the patch has not been tested with the custom payment application. Which risk response strategy is being considered?

Easy
70

A multinational organization is implementing a risk mitigation strategy for a critical system. The business impact analysis shows that downtime costs are extremely high. Which risk response strategy is MOST appropriate for this scenario?

Hard
71

Which THREE of the following are key components of an effective risk treatment plan?

Hard
72

Put the steps for performing a control self-assessment (CSA) in order.

Medium
73

A risk assessment identifies a high likelihood of a data breach due to insecure APIs. The risk team proposes disabling the APIs until they are secured, implementing a WAF, and purchasing breach insurance. Which THREE risk response options are being considered?

Hard
74

A healthcare organization is required by regulation to retain patient records for seven years. The risk manager is evaluating a new cloud storage solution that offers encryption at rest but stores data in multiple jurisdictions. Which of the following is the MOST critical risk consideration when selecting this solution?

Hard
75

A company is implementing a new cloud-based customer relationship management (CRM) system. The risk manager has identified that the vendor's security controls may not meet the company's requirements. Which of the following is the BEST way to address this risk?

Hard
76

Based on the exhibit, what is the primary risk response strategy demonstrated by this firewall rule?

Easy
77

A healthcare organization's risk register shows that a critical server lacks vendor support and has a high inherent risk of failure. The risk owner proposes to implement redundant hardware and a failover cluster. The cost of the redundancy is $200,000, while the estimated annual loss from failure is $150,000. Which factor is MOST important for the risk practitioner to consider when evaluating this proposed risk response?

Hard
78

A recent security assessment identified that a critical web application is vulnerable to SQL injection due to unpatched software. The vendor has released a security patch. Which risk response is most appropriate?

Easy
79

Which THREE of the following are key considerations when selecting a risk response option?

Medium
80

A small e-commerce company has identified a high-risk vulnerability in its payment processing system that could expose customer credit card data. The IT team recommends immediately patching the system, but the patch requires a 4-hour downtime during peak sales hours. The risk manager proposes accepting the risk until the next scheduled maintenance window in two weeks. The CEO is concerned about potential fines from PCI DSS non-compliance. What is the BEST course of action?

Easy
81

A software development company identifies that developers are storing API keys in plaintext within source code repositories. The risk practitioner proposes a risk treatment plan that includes implementing a secrets management solution and rotating all exposed keys. The Chief Technology Officer asks how the risk practitioner will confirm that the treatment plan is reducing the risk over time. Which metric is MOST appropriate for monitoring the effectiveness of this risk response?

Easy
82

A risk manager is reviewing the risk treatment plan for a new mobile banking application. The plan includes implementing multi-factor authentication (MFA) and conducting regular vulnerability scans. The risk manager wants to ensure that the controls are operating effectively. Which of the following should be performed to verify the effectiveness of the controls?

Medium
83

Which TWO of the following are examples of risk transfer? (Select TWO.)

Medium
84

A healthcare organization is migrating its electronic health records (EHR) system to a cloud provider. The risk assessment shows that the cloud provider has strong security certifications (e.g., SOC 2 Type II, ISO 27001). However, the organization's legal team is concerned about data sovereignty laws that require patient data to remain within the country. The cloud provider's data centers are located in three regions: one in-country, and two outside. The project manager proposes using only the in-country data center. The IT director warns that this will increase latency and reduce redundancy. The risk manager must propose a response. Which is the BEST option?

Hard
85

Match each risk management term to its definition.

Medium
86

A financial services firm has determined that a critical trading application cannot be patched for a known remote code execution vulnerability because the vendor no longer supports the platform. The risk manager decides to deploy a web application firewall (WAF) with virtual patching and network segmentation to isolate the application from the internal network. Which risk response strategy does this represent?

Medium
87

A retail company is launching a new e-commerce platform. The risk management team has identified that the platform's payment gateway integration could be exploited to intercept customer credit card data. The team proposes several controls. Which of the following are examples of risk mitigation controls? (Choose two.)

Medium
88

An organization purchases cyber insurance to cover potential losses from data breaches. This is an example of:

Easy
89

A multinational bank is subject to GDPR and local data protection laws. The risk practitioner is reviewing a risk treatment plan for a new customer analytics platform that will process personal data across three jurisdictions. The plan proposes to rely on the vendor's standard contractual clauses (SCCs) as the primary control for cross-border data transfers. Which factor is MOST important for the risk practitioner to evaluate when assessing the adequacy of this risk response?

Hard
90

A risk assessment reveals that a legacy system has a high likelihood of failure. The system is critical and cannot be replaced immediately. The company decides to implement manual overrides and additional monitoring. This is an example of:

Medium
91

After a risk assessment, a company decides to stop using a third-party service that has high residual risk. This is an example of:

Easy
92

After implementing multiple controls, the residual risk for a new product launch is still slightly above the risk appetite. The risk manager decides to proceed with the launch and monitor the risks regularly. This is:

Hard
93

Which THREE of the following are key components of an effective risk response plan?

Medium
94

A risk assessment identifies that a legacy system has a high risk of failure with no available vendor support. The organization decides to decommission the system and migrate to a modern platform. This is:

Hard

Frequently asked questions

What does the Risk Response and Mitigation domain cover on the CRISC exam?
Be able to pick the correct risk response for a scenario, order treatment steps, and classify controls. The key is recognizing that residual risk above appetite requires explicit acceptance by the accountable owner, not silent continuation.
How many questions are in this domain?
This page lists all 94 Risk Response and Mitigation questions in the CRISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Risk Response and Mitigation questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isaca-crisc ISACA-CRISC risk response mitigation Practice Questions