Courseiva

CCNA Risk Response and Mitigation Questions

75 of 94 questions · Page 1/2 · Risk Response and Mitigation · Answers revealed

1
MCQmedium

A risk assessment reveals that the cost of implementing a control ($500k) exceeds the annualized loss expectancy (ALE) of $300k. The risk is currently within the organization's risk appetite. What is the appropriate risk response?

A.Accept the risk
B.Implement the control
C.Avoid the risk
D.Transfer the risk
AnswerA

Acceptance is appropriate because the control's cost exceeds the ALE it would reduce, so the expenditure is not justified, and the residual risk already sits within the organisation's stated risk appetite. No further treatment is warranted beyond monitoring.

Why this answer

When the cost of a control exceeds the ALE and the risk is already within the organization's risk appetite, accepting the risk is the economically justified response. Spending $500k to mitigate a $300k annualized loss is not cost-effective, and the risk is tolerable by definition.

Exam trap

CRISC often tests whether candidates reflexively choose 'implement the control' without checking cost-benefit, ignoring that acceptance is valid when the risk is within appetite.

How to eliminate wrong answers

Option B is wrong because implementing a control that costs more than the expected loss destroys value and is not justified when the risk is already within appetite. Option C is wrong because risk avoidance means eliminating the activity entirely, which is disproportionate here and not indicated by the cost-benefit analysis. Option D is wrong because risk transfer (e.g., insurance) is not warranted when the risk is acceptable and the control cost already exceeds the ALE.

2
MCQeasy

A small retail company has determined that the risk of a point-of-sale (POS) system malware infection is high. The company decides to implement a whitelisting solution that only allows approved applications to run on POS terminals. This is an example of which risk response?

A.Risk acceptance
B.Risk mitigation
C.Risk avoidance
D.Risk transfer
AnswerB

Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. The whitelisting solution prevents unauthorized applications from running, thereby reducing the likelihood of malware infection on POS terminals. This is a classic example of a preventive control that mitigates risk. The company is actively reducing the risk to an acceptable level, which aligns with the risk mitigation strategy.

Why this answer

The company is implementing a whitelisting solution to prevent malware on POS terminals. This is a preventive control that reduces the likelihood of the risk occurring. Risk mitigation is the correct response because it involves taking action to reduce the probability or impact of a risk.

Risk acceptance would mean doing nothing, risk transfer would involve shifting the financial impact, and risk avoidance would mean eliminating the activity. Since the company is actively reducing the risk while continuing the activity, it is mitigation.

Exam trap

The trap here is confusing mitigation with avoidance; avoidance would require stopping the use of POS systems, while mitigation reduces risk while continuing the activity.

3
MCQeasy

A company has identified a critical vulnerability in a legacy application that cannot be patched immediately. The application is used by a small number of users and supports a non-critical business process. Which of the following is the MOST appropriate risk response strategy?

A.Avoidance
B.Transfer
C.Acceptance
D.Mitigation
AnswerC

Acceptance suits this scenario because the residual risk falls within tolerance: the vulnerability affects a legacy application serving few users on a non-critical process, and patching is not immediately feasible. Formally documenting and monitoring that accepted exposure satisfies the stem's constraints, whereas mitigation, transfer or avoidance would demand disproportionate cost or effort.

Why this answer

Acceptance is the most appropriate response because the vulnerability exists in a legacy application that supports a non-critical business process and is used by a small number of users. The cost and operational impact of patching or replacing the application outweigh the risk, making it acceptable to operate with the known vulnerability under formal risk acceptance.

Exam trap

The trap here is that candidates often choose mitigation by default, failing to recognize that when a vulnerability cannot be patched and the asset is low-impact, formal acceptance is the correct risk response per the CRISC framework.

How to eliminate wrong answers

Option A is wrong because avoidance would require removing the application or the process entirely, which is unnecessary for a non-critical process with limited user exposure. Option B is wrong because transfer (e.g., via cyber insurance or outsourcing) does not eliminate the technical vulnerability; it only shifts financial liability, and the underlying risk remains in the application. Option D is wrong because mitigation (e.g., applying a vendor patch, implementing a WAF rule, or hardening the host) is not immediately feasible for a legacy application that cannot be patched, and the low business impact does not justify the effort.

4
MCQmedium

After implementing a set of controls, the risk owner calculates the residual risk and finds it is still above the risk tolerance. However, the cost to further reduce the risk exceeds the potential loss. What is the MOST appropriate next step?

A.Formally accept the residual risk
B.Re-assess the inherent risk
C.Reduce current controls to lower costs
D.Implement additional controls despite the cost
AnswerA

When residual risk remains above tolerance but further treatment costs exceed the potential loss, formal risk acceptance is the appropriate response. The risk owner documents the decision and escalates to the appropriate authority for sign-off, rather than spending disproportionately on mitigation.

Why this answer

When the residual risk remains above the risk tolerance but the cost of further mitigation exceeds the potential loss, the most appropriate step is to formally accept the residual risk. This decision is based on a cost-benefit analysis showing that additional controls are not economically justified. The risk owner documents the acceptance, acknowledging the remaining exposure within the organization's risk appetite framework.

Exam trap

The CRISC exam often tests the misconception that residual risk must always be reduced to zero or below tolerance regardless of cost, but the correct approach is to accept risk when further mitigation is economically unjustified.

How to eliminate wrong answers

Option B is wrong because re-assessing inherent risk does not address the fact that residual risk is already calculated and above tolerance; inherent risk is the starting point, not the solution to an economic decision. Option C is wrong because reducing current controls would likely increase residual risk further, moving it even farther from tolerance and potentially violating compliance or security baselines. Option D is wrong because implementing additional controls despite the cost violates the fundamental principle of cost-benefit analysis in risk management; it would waste resources without proportional risk reduction.

5
MCQmedium

An organization's security team recommends implementing a web application firewall (WAF) to protect against SQL injection attacks. The risk manager evaluates the cost of the WAF and the likelihood of a successful attack. This evaluation is BEST described as:

A.Residual risk calculation
B.Inherent risk assessment
C.Cost-benefit analysis
D.Risk acceptance
AnswerC

Cost-benefit analysis weighs the WAF's implementation cost against the reduced likelihood and impact of a successful SQL injection attack, which is exactly the comparison described. Control selection and risk assessment lack the explicit monetary trade-off, while residual risk evaluation occurs after treatment.

Why this answer

The risk manager is comparing the cost of implementing the WAF against the likelihood and potential impact of a SQL injection attack. This direct comparison of mitigation cost to risk reduction benefit is the essence of a cost-benefit analysis, which determines whether the control is economically justified. It is not a calculation of residual or inherent risk, nor is it an acceptance decision.

Exam trap

The trap here is that candidates confuse the evaluation of a control's cost against risk reduction with inherent risk assessment, but inherent risk is calculated without any controls in place, whereas this scenario explicitly involves weighing the cost of a specific control against the risk it mitigates.

How to eliminate wrong answers

Option A is wrong because residual risk calculation determines the risk remaining after controls are implemented, not the evaluation of whether to implement a control in the first place. Option B is wrong because inherent risk assessment evaluates the risk level before any controls are applied, without considering the cost of mitigation. Option D is wrong because risk acceptance is a formal decision to tolerate a risk without implementing additional controls, which is not what is happening when the manager evaluates the cost of a proposed control.

6
MCQhard

A company has implemented a risk mitigation plan that includes technical controls. However, six months later, the residual risk is still higher than expected. The risk practitioner suspects that the controls are not being followed. Which of the following is the BEST approach to verify this?

A.Perform a new risk assessment
B.Interview control owners
C.Review risk register updates
D.Conduct a control testing and audit review
AnswerD

Control testing and audit review examines whether the technical controls operate as designed and whether staff actually follow them, directly addressing the suspected compliance gap. It produces evidence of control effectiveness, confirming whether residual risk remains elevated because of non-adherence rather than poor control design.

Why this answer

Conducting a control testing and audit review directly assesses whether controls are operating as intended, providing evidence of compliance or non-compliance. This is the most effective way to verify if controls are being followed. Option A (perform a new risk assessment) is indirect and does not focus on control effectiveness.

Option B (interview control owners) relies on self-reporting and may not be objective. Option C (review risk register updates) does not provide evidence of actual control operation.

7
MCQmedium

A software company has identified that a critical third-party library used in its product has a known remote code execution vulnerability. The vendor has not released a patch, and the product is used by customers who cannot accept downtime. The risk practitioner recommends isolating the library's functionality in a sandboxed process with restricted permissions. Which risk response strategy does this represent?

A.Risk mitigation
B.Risk avoidance
C.Risk transfer
D.Risk acceptance
AnswerA

Sandboxing the vulnerable library reduces the impact of exploitation by restricting the code's access to system resources. This is a compensating control that lowers risk while a patch is unavailable. Mitigation is the correct strategy because the company is implementing a control to reduce the likelihood or impact of the vulnerability without eliminating the functionality.

Why this answer

Sandboxing the vulnerable library is a mitigation response because it adds a compensating control that reduces the impact of a potential exploit. Since no patch is available and downtime is not acceptable, mitigation through isolation is the most practical strategy. This approach lowers risk while maintaining product availability for customers.

Exam trap

The trap here is assuming that because the patch is unavailable, the only options are accept or avoid, when compensating controls like sandboxing constitute mitigation.

8
MCQmedium

A hospital's risk team has documented that its infusion pump fleet runs an unsupported operating system, creating a high risk of compromise. Replacing the pumps requires capital approval that will take 18 months, and the pumps cannot be taken offline in the interim. Which risk response is MOST appropriate for the risk practitioner to recommend?

A.Implement compensating controls such as network segmentation and strict access controls until the pumps are replaced.
B.Avoid the risk by immediately decommissioning all infusion pumps and switching to manual dosing.
C.Accept the risk and log it in the risk register for the next annual review.
D.Transfer the risk by purchasing cyber liability insurance that covers medical device incidents.
AnswerA

When the primary fix (replacement) is delayed, compensating controls reduce likelihood and impact in the interim. Segmenting the pumps onto a dedicated VLAN, restricting inbound/outbound traffic, and enforcing least-privilege access directly lower the exposure of the unsupported OS. This is a practical mitigation that maintains clinical availability while the capital project proceeds.

Why this answer

The best response is to reduce risk through compensating controls while the long-term replacement is planned. Because the pumps cannot be removed and replacement is 18 months away, the risk practitioner should recommend interim mitigation that lowers exposure without disrupting patient care. This aligns with the CRISC principle of selecting a response proportionate to risk and maintaining operations.

Exam trap

The trap here is assuming that because the root fix is delayed, the only options are accept or avoid, when compensating controls can meaningfully reduce risk in the interim.

9
MCQeasy

A security team identifies a critical vulnerability in a web application that cannot be patched immediately. They deploy a web application firewall (WAF) to block exploitation attempts. This is an example of:

A.Risk Transfer
B.Risk Mitigation
C.Risk Avoidance
D.Risk Acceptance
AnswerB

A WAF blocks exploitation attempts, reducing the likelihood of the vulnerability being realised while patching is deferred. This lowers residual risk rather than transferring it via insurance or avoiding the application, satisfying the stem's constraint of an unpatched critical flaw requiring interim protection.

Why this answer

Deploying a WAF to block exploitation attempts directly reduces the likelihood and/or impact of the vulnerability being exploited, which is the definition of risk mitigation. The WAF acts as a compensating control, filtering malicious traffic (e.g., SQL injection, XSS payloads) at the application layer (HTTP/HTTPS) without patching the underlying code. This aligns with the CRISC domain of Risk Response and Mitigation, where controls are implemented to bring residual risk within acceptable tolerance.

Exam trap

The CRISC exam often tests the distinction between risk mitigation (implementing a control to reduce risk) and risk avoidance (eliminating the activity entirely), so candidates mistakenly choose avoidance when they see a vulnerability that cannot be patched, but the key is that the application remains in use with a compensating control.

How to eliminate wrong answers

Option A is wrong because risk transfer involves shifting the financial impact of a risk to a third party (e.g., purchasing cyber insurance or outsourcing to a managed security provider), not deploying a technical control like a WAF. Option C is wrong because risk avoidance would require ceasing the activity that introduces the risk (e.g., taking the web application offline or removing the vulnerable feature entirely), not implementing a control to allow continued operation. Option D is wrong because risk acceptance means formally acknowledging the risk and taking no action to reduce it, whereas deploying a WAF is an active countermeasure that reduces the risk level.

10
MCQhard

Based on the risk register exhibit, which of the following is the MOST appropriate risk response for R-0042?

A.Mitigate the risk by implementing additional encryption controls
B.Transfer the risk to a third-party insurer
C.Avoid the risk by discontinuing storage of PII
D.Accept the risk and continue monitoring
AnswerD

Acceptance suits R-0042 because its residual risk sits within tolerance and treatment costs exceed the potential loss. Monitoring keeps the exposure visible so it is re-evaluated if likelihood or impact changes, satisfying the register's response requirement.

Why this answer

R-0042 is a low-likelihood, low-impact risk involving PII stored with AES-256 encryption and strict access controls. The residual risk is within the organization's risk appetite, making acceptance with continued monitoring the most appropriate response. Mitigation, transfer, or avoidance would introduce unnecessary cost or operational disruption for a risk already well-controlled.

Exam trap

The trap here is that candidates often assume any risk involving PII must be mitigated or avoided, ignoring the risk register's explicit low-likelihood and low-impact ratings and the existing strong controls, which make acceptance the most cost-effective and appropriate response.

How to eliminate wrong answers

Option A is wrong because the risk register shows encryption (AES-256) is already implemented, so adding further encryption controls would provide negligible risk reduction and is not cost-effective. Option B is wrong because transferring the risk to a third-party insurer is typically reserved for high-impact, low-frequency risks (e.g., data breach liability), not for a low-impact, low-likelihood risk already within appetite. Option C is wrong because discontinuing storage of PII would avoid the risk entirely but is a drastic measure that would disrupt business operations and is disproportionate to the low severity of R-0042.

11
MCQeasy

A global manufacturing company is implementing a new ERP system across multiple regions. The project manager has identified a risk that data migration from legacy systems may cause data corruption, leading to production delays. The risk owner proposes conducting a full data reconciliation after migration. However, the IT director argues that this would be too time-consuming and suggests only sampling data for verification. The risk manager must decide on the risk response. The project timeline is tight, and the company has a low tolerance for data integrity issues. Which of the following is the BEST course of action?

A.Accept the risk and proceed with data sampling to save time
B.Avoid the risk by postponing the ERP implementation
C.Implement the full data reconciliation as proposed by the risk owner
D.Transfer the risk by purchasing insurance for data corruption
AnswerC

Full reconciliation matches every migrated record against the legacy source, detecting all corruption rather than extrapolating from samples. Given the tight timeline but low tolerance for data integrity issues, this response aligns with the organisation's stated risk appetite and avoids production delays from undetected errors.

Why this answer

Full data reconciliation is the correct risk response because the company has a low tolerance for data integrity issues and the risk of data corruption could cause production delays. While time-consuming, this approach directly mitigates the identified risk by ensuring all migrated data is verified, aligning with the risk appetite. Sampling would leave a margin of error unacceptable for a low-tolerance environment, and the other options either fail to address the risk or are impractical.

Exam trap

The trap here is that candidates may choose data sampling (Option A) as a compromise to save time, overlooking that the company's low tolerance for data integrity issues demands full verification, not a statistical shortcut.

How to eliminate wrong answers

Option A is wrong because accepting the risk with data sampling ignores the company's low tolerance for data integrity issues and could leave undetected corruption that causes production delays. Option B is wrong because avoiding the risk by postponing the ERP implementation is an extreme overreaction that does not address the immediate need for migration and would cause significant business disruption. Option D is wrong because transferring the risk via insurance does not prevent data corruption or production delays; it only provides financial compensation after the fact, which does not meet the requirement for data integrity.

12
Multi-Selectmedium

A company has a critical production system with a known vulnerability. Due to the system's age, the vendor no longer supports it. The company decides to implement network segmentation and purchase cyber insurance to cover potential losses. Which TWO risk response options are they applying?

Select 2 answers
A.Accept
B.Transfer
C.Avoid
D.Ignore
E.Mitigate
AnswersB, E

Insurance transfers financial risk.

Why this answer

Network segmentation reduces the attack surface by isolating the vulnerable system, which is a classic risk mitigation technique. Purchasing cyber insurance transfers the financial risk of residual losses to a third party, making 'Transfer' the correct second option. Together, these actions address the risk without removing the vulnerability.

Exam trap

The trap here is that candidates confuse 'transfer' with 'mitigate' because insurance is a financial transfer, while segmentation is a technical mitigation, and the question expects you to recognize both as distinct, simultaneous responses.

13
MCQhard

After implementing security controls, a risk assessment shows a residual risk of data exfiltration with a probability of 5% and potential loss of $10 million. The organization's risk appetite allows a maximum acceptable risk level of 3% probability for such impact. The cost of further mitigation is $1 million. What is the best risk response?

A.Implement additional controls to reduce probability to 2%
B.Accept the residual risk
C.Purchase cybersecurity insurance
D.Discontinue the process
AnswerA

Further mitigation brings risk within appetite.

Why this answer

The residual risk has a probability of 5% and a potential loss of $10 million, resulting in an expected loss of $500,000. The organization's risk appetite allows a maximum probability of 3% for such an impact, so the current risk exceeds the acceptable threshold. Implementing additional controls for $1 million to reduce the probability to 2% brings the risk within the risk appetite (expected loss of $200,000) and is cost-effective because the reduction in expected loss ($300,000) is less than the control cost, but the primary driver is compliance with risk appetite, not pure cost-benefit.

Exam trap

The trap here is that candidates focus on the cost-benefit analysis (mitigation cost vs. reduced expected loss) and incorrectly conclude that acceptance is cheaper, ignoring that risk appetite is a binding constraint that overrides pure financial calculations.

How to eliminate wrong answers

Option B is wrong because accepting the residual risk would violate the organization's risk appetite, which explicitly caps probability at 3% for this impact level; acceptance is only valid when risk is within tolerance. Option C is wrong because purchasing cybersecurity insurance transfers financial risk but does not reduce the probability of data exfiltration; it would still leave the probability at 5%, exceeding the risk appetite threshold, and insurance premiums often require residual risk to be within appetite. Option D is wrong because discontinuing the process is an extreme risk avoidance response that would eliminate the business function entirely, which is disproportionate when a cost-effective mitigation exists to bring risk within appetite.

14
MCQhard

A software development company uses a third-party cloud provider to host its source code repositories. The risk practitioner discovers that the provider's contract does not include a right-to-audit clause. The provider has a strong security reputation but is unwilling to add the clause. The company's risk appetite for third-party risk is low. Which action should the risk practitioner recommend FIRST?

A.Terminate the contract and migrate the source code to an in-house data center.
B.Request that the provider provide a SOC 2 Type II report as a compensating control.
C.Accept the risk because the provider has a strong security reputation.
D.Conduct a risk assessment to determine the potential impact of the missing right-to-audit clause.
AnswerD

Before deciding on a risk response, the risk practitioner must first assess the risk. The missing right-to-audit clause could limit the company's ability to verify the provider's security controls, potentially increasing risk. A formal risk assessment will quantify the impact and likelihood, enabling an informed decision that aligns with the company's low risk appetite.

Why this answer

The first step in risk response is to assess the risk. The missing right-to-audit clause creates uncertainty about the provider's security controls, which is particularly concerning given the low risk appetite. A risk assessment will evaluate the likelihood and impact, allowing the risk practitioner to recommend an appropriate response, such as negotiating alternative assurance, accepting with compensating controls, or terminating the contract.

Exam trap

The trap here is jumping to a response like termination or acceptance without first assessing the risk, or assuming that a SOC 2 report fully compensates for the lack of a right-to-audit clause.

15
MCQhard

A multinational corporation is implementing a risk treatment plan for a critical vendor that has poor security controls. The risk practitioner has recommended contract renegotiation to include security requirements, but the vendor refuses. The business unit insists on continuing the relationship due to cost savings. The risk practitioner's next step should be to:

A.Document the risk in the risk register and continue monitoring without escalation.
B.Escalate the issue to the risk committee for a decision on risk acceptance.
C.Implement compensating controls internally to reduce the vendor risk.
D.Terminate the vendor relationship immediately without further discussion.
AnswerB

When a risk exceeds appetite and the business unit is unwilling to mitigate, the risk practitioner must escalate to the risk committee or appropriate governance body for a formal risk acceptance decision. This ensures that the decision is made at the right level and documented. The risk practitioner does not have authority to accept risk on behalf of the organization.

Why this answer

The risk practitioner must escalate to the risk committee when the business unit refuses to mitigate a risk that exceeds appetite. The committee has the authority to accept the risk on behalf of the organization. Simply documenting or implementing controls without addressing the governance gap would leave the organization exposed without proper oversight.

Exam trap

The trap here is assuming that documenting the risk or applying compensating controls is sufficient, bypassing the need for formal escalation and risk acceptance by the appropriate authority.

16
MCQmedium

A risk practitioner at a financial services firm is updating the risk register. For a risk involving unauthorized access to the customer database, the risk owner has decided to purchase a cyber liability insurance policy that covers breach-related costs. Which risk response option has the risk owner selected?

A.Risk acceptance
B.Risk mitigation
C.Risk transfer
D.Risk avoidance
AnswerC

Purchasing insurance shifts the financial impact of a risk to a third party. This is a classic example of risk transfer, where the organization pays a premium to transfer the potential financial loss. The risk itself (unauthorized access) is not eliminated, but the financial consequences are shared or shifted to the insurer, which is a valid risk response under CRISC.

Why this answer

The risk owner chose to purchase insurance, which is a financial arrangement that shifts the potential loss to an insurer. This is a textbook example of risk transfer. The other options do not match because the organization is not eliminating the activity (avoidance), not implementing controls to reduce likelihood or impact (mitigation), and not simply bearing the risk without action (acceptance).

Exam trap

The trap here is confusing risk transfer with risk mitigation because both involve taking action, but transfer specifically shifts financial impact to a third party while mitigation reduces the risk itself.

17
MCQeasy

A risk assessment reveals that a data center is located in a flood-prone area. The organization decides to build a secondary data center in a different region and replicate critical data between both sites. This is an example of which risk response?

A.Risk acceptance
B.Risk mitigation
C.Risk avoidance
D.Risk transfer
AnswerB

Building a secondary data centre in a different region directly reduces the likelihood and impact of flood disruption, satisfying the risk-assessment finding. Risk mitigation lowers risk through controls or redundancy, unlike avoidance (eliminating the activity), transfer (insurance), or acceptance. Replicating critical data to a separate site is a concrete mitigating control.

Why this answer

Building a secondary data center in a different region and replicating critical data between both sites reduces the likelihood and impact of a flood-related outage. This is a classic risk mitigation response because it implements controls (geographic redundancy, data replication) to lower residual risk to an acceptable level, without eliminating the original flood risk entirely.

Exam trap

The trap here is confusing risk mitigation (reducing impact via redundancy) with risk avoidance (eliminating the threat by moving), leading candidates to incorrectly select risk avoidance when the primary site is not decommissioned.

How to eliminate wrong answers

Option A is wrong because risk acceptance would involve acknowledging the flood risk and taking no proactive action, which is not the case here. Option C is wrong because risk avoidance would require relocating the primary data center away from the flood-prone area entirely, not building a secondary site while keeping the original operational. Option D is wrong because risk transfer would involve shifting the financial impact of a flood to a third party (e.g., via insurance or outsourcing), not deploying technical redundancy controls.

18
MCQhard

A multinational corporation is deploying a new IoT-based inventory management system across its warehouses. The risk practitioner identifies that the IoT devices use default administrative credentials and unencrypted communication protocols. The vendor states that a firmware update to address these issues will not be available for six months. The business cannot delay the deployment due to competitive pressures. Which risk response strategy is MOST appropriate in this situation?

A.Accept the risk and proceed with deployment, documenting the decision and implementing compensating controls such as network segmentation and monitoring.
B.Transfer the risk by purchasing cyber insurance that covers IoT-related breaches.
C.Avoid the risk by canceling the IoT deployment and continuing with the existing manual inventory process.
D.Mitigate the risk by immediately replacing the IoT devices with a different vendor's products that have better security features.
AnswerA

When a risk cannot be avoided or mitigated immediately due to business constraints, acceptance with compensating controls is appropriate. Network segmentation and monitoring reduce the likelihood and impact of exploitation. Documenting the decision ensures accountability and provides a basis for future risk reassessment once the firmware update is available.

Why this answer

Given the business imperative to deploy and the unavailability of a timely patch, risk acceptance with compensating controls is the most appropriate response. This approach acknowledges the residual risk while reducing it through segmentation and monitoring. It also documents the decision for future review, aligning with CRISC principles of balancing risk and business objectives.

Exam trap

The trap here is assuming that risk transfer through insurance or avoidance is always preferable, when in fact business constraints often necessitate risk acceptance with compensating controls.

19
MCQeasy

A retail company has identified that its point-of-sale (POS) terminals are running an outdated operating system that no longer receives security patches. The risk practitioner recommends upgrading the terminals to a supported OS. The cost of the upgrade is $500,000, while the estimated annual loss from a potential breach is $2,000,000 with a 30% likelihood. Which risk response strategy is being recommended?

A.Risk avoidance
B.Risk acceptance
C.Risk mitigation
D.Risk transfer
AnswerC

Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. Upgrading the POS terminals to a supported OS reduces the likelihood of exploitation of unpatched vulnerabilities. This is a classic example of mitigation, as the action directly addresses the vulnerability and lowers the risk to an acceptable level.

Why this answer

Upgrading the POS terminals to a supported operating system is a mitigation strategy because it reduces the likelihood of a breach by addressing the unpatched vulnerability. The cost-benefit analysis ($500,000 upgrade vs. $600,000 expected annual loss) supports this action. Mitigation is appropriate when controls can reduce risk to an acceptable level.

Exam trap

The trap here is confusing mitigation with avoidance or transfer. Mitigation reduces risk through controls, while avoidance eliminates the activity and transfer shifts financial impact.

20
MCQeasy

A healthcare organization is required by law to retain patient records for seven years. The IT department proposes storing backups on tapes that are kept in an on-site vault. The risk manager notes that the on-site vault is in a flood zone. Which risk response strategy is being applied if the organization decides to move the tapes to a secure off-site facility in a different geographic region?

A.Risk mitigation
B.Risk acceptance
C.Risk transfer
D.Risk avoidance
AnswerA

Moving backups to an off-site facility in a different geographic region reduces the risk of loss from a flood. This is a mitigation strategy because it implements a control (geographic separation) to lower the likelihood or impact of a disaster. The organization still retains records but with reduced risk.

Why this answer

The correct answer is risk mitigation. By moving backups to an off-site facility, the organization implements a control that reduces the risk of flood damage. This is a classic example of mitigation, where the goal is to lower the probability or impact of a threat, rather than avoiding the activity or transferring the risk.

Exam trap

The trap here is confusing mitigation with avoidance; moving data to a safer location reduces risk but does not eliminate the activity that creates the risk.

21
MCQhard

A financial services firm operates a high-volume transaction processing platform. During a risk assessment, the risk owner determines that the residual risk of database corruption exceeds the risk appetite. The database vendor offers a patch that reduces the vulnerability but requires a 12-hour outage. Business stakeholders refuse the outage. The risk practitioner is asked to recommend a risk response that aligns with the risk appetite without disrupting operations. Which of the following is the BEST recommendation?

A.Avoid the risk by decommissioning the transaction platform and migrating to a new solution.
B.Implement database replication to a secondary node and fail over during a maintenance window, then apply the patch.
C.Accept the residual risk and document it in the risk register with a review date in six months.
D.Transfer the risk by purchasing cyber liability insurance that covers data corruption events.
AnswerB

Replication provides a compensating control that maintains availability while the patch is applied to the primary node, allowing the outage to be absorbed by failover. This reduces the corruption risk to within appetite without a full 12-hour business outage. It is a mitigation strategy that balances technical remediation with business continuity requirements.

Why this answer

The best response reduces residual risk to within appetite while respecting the business constraint against a 12-hour outage. Database replication provides a compensating control that enables patching with minimal downtime, effectively mitigating the vulnerability. Acceptance, transfer, and avoidance either leave risk above appetite or introduce unacceptable business disruption.

Exam trap

The trap here is assuming that because the business refuses downtime, the only options are acceptance or avoidance, ignoring compensating controls that enable mitigation.

22
MCQmedium

A multinational corporation has adopted a risk mitigation strategy for its key suppliers by requiring them to maintain ISO 27001 certification. During an audit, the risk manager discovers that one critical supplier lost its certification six months ago but did not report it, as contractually required. The supplier still has adequate security controls in place, and the relationship is strategically important. The CEO wants to avoid contract termination. What is the MOST appropriate risk response?

A.Issue a corrective action plan requiring the supplier to regain certification within three months, with monthly progress reviews.
B.Transfer the risk to the supplier's cyber liability insurance policy.
C.Accept the risk because the supplier still has effective controls, and update the risk register.
D.Terminate the contract immediately and find an alternative supplier.
AnswerA

A corrective action plan with monthly reviews addresses the contractual breach and certification lapse while preserving the strategic relationship, satisfying the CEO's wish to avoid termination. It imposes measurable remediation deadlines rather than accepting or transferring the supplier risk outright.

Why this answer

The most appropriate risk response is to issue a corrective action plan with a deadline and monitoring, because it directly addresses the control gap (lapsed certification) while preserving the strategic relationship. ISO 27001 certification is a contractual requirement and a key risk mitigation control; its loss increases risk even if other controls exist. A corrective action plan is a targeted risk treatment that restores compliance and provides assurance through monthly reviews, aligning with CRISC's emphasis on balancing risk and business objectives.

Exam trap

CRISC often tests the misconception that risk acceptance is always acceptable if controls are present, but the key is that contractual non-compliance and loss of independent assurance require a formal response; candidates may overlook the need to address the root cause through a corrective action plan.

How to eliminate wrong answers

Option B is wrong because transferring risk via the supplier's insurance does not address the root cause (loss of certification) and may not cover contractual non-compliance; insurance is a financial risk transfer, not a control restoration. Option C is wrong because accepting the risk solely based on existing controls ignores the contractual breach and the fact that certification provides independent assurance; acceptance without treatment may be inappropriate for a critical supplier. Option D is wrong because immediate termination is a disproportionate response that could disrupt operations and damage a strategically important relationship, and it does not consider less disruptive alternatives like corrective action.

23
MCQmedium

A financial services firm has a risk register entry for a core banking application with an inherent risk score of 9 (high). The risk owner implements a new database activity monitoring tool and role-based access reviews. After implementation, the residual risk score is reassessed at 6 (medium). The risk owner now wants to formally document that the risk has been reduced to an acceptable level. Which action should the risk practitioner recommend NEXT?

A.Update the risk register to reflect the new residual risk score and obtain risk owner sign-off.
B.Escalate the residual risk to the board of directors for approval.
C.Initiate a new risk assessment to identify any remaining vulnerabilities.
D.Perform a penetration test to validate the effectiveness of the new controls.
AnswerA

Updating the risk register with the reassessed residual risk score and obtaining formal risk owner acceptance ensures the risk treatment is documented and the risk is owned at the appropriate level. This aligns with CRISC practices for maintaining an accurate risk profile and confirming that residual risk aligns with risk appetite.

Why this answer

After implementing risk mitigation controls, the risk practitioner must ensure the risk register is updated with the new residual risk score and that the risk owner formally accepts the remaining risk. This confirms that the risk treatment has been effective and that the residual risk is within the defined risk appetite. Documentation and sign-off are essential for auditability and governance.

Exam trap

The trap here is assuming that additional technical testing or escalation is always required after control implementation, rather than focusing on the fundamental step of updating the risk register and obtaining risk owner acceptance.

24
MCQhard

A multinational corporation has a risk register entry for a potential data breach of customer information. The risk owner has decided to purchase cyber insurance to cover financial losses from a breach. Which of the following BEST describes the residual risk after this risk response?

A.The residual risk remains, but the financial impact is partially transferred to the insurer.
B.The residual risk is reduced to zero because the risk has been transferred.
C.The residual risk is increased because the insurance policy may not cover all breach scenarios.
D.The residual risk is eliminated because the insurance covers all financial losses.
AnswerA

Purchasing cyber insurance is a risk transference strategy that shifts some financial consequences to the insurer. However, the organization still bears residual risk such as reputational harm, loss of customer trust, and any costs exceeding policy limits or not covered. Thus, the residual risk remains but with reduced financial exposure.

Why this answer

Cyber insurance transfers a portion of the financial risk to the insurer, but the organization retains residual risk, including non-financial impacts and any uncovered losses. The residual risk is not eliminated or reduced to zero; it remains but with a lower financial exposure. This is a key concept in risk response: transference does not remove all risk.

Exam trap

The trap here is assuming that insurance eliminates all risk, when in reality it only transfers some financial impact and leaves residual risk.

25
MCQhard

A risk practitioner is working with the IT team to design controls for a new cloud-based human resources system. The team proposes using encryption for data at rest and in transit, role-based access controls, and regular backups. The risk practitioner notes that these controls address confidentiality, integrity, and availability. Which of the following should the risk practitioner recommend to ensure the controls remain effective over time?

A.Document the controls in the risk register and review them during the next audit.
B.Perform a penetration test after the system goes live and then every two years.
C.Conduct an annual risk assessment to re-evaluate the risks and controls.
D.Implement a continuous monitoring program that includes automated alerts for control failures.
AnswerD

Continuous monitoring ensures that controls remain effective by providing real-time or near-real-time visibility into control performance. Automated alerts can notify the team of failures or deviations, enabling prompt remediation. This is a proactive approach to maintain risk at acceptable levels and is a key recommendation for sustaining control effectiveness in dynamic environments like cloud systems.

Why this answer

Continuous monitoring with automated alerts ensures that controls are consistently effective by detecting failures or deviations quickly. In a cloud environment, where changes are frequent, periodic assessments or audits are insufficient. Continuous monitoring provides ongoing assurance and supports timely risk response, aligning with CRISC best practices for maintaining risk within appetite.

Exam trap

The trap here is opting for periodic assessments like annual risk assessments or audits, which do not provide the timely detection needed for dynamic cloud environments.

26
MCQhard

A third-party vendor's security assessment reveals multiple high-risk findings related to data handling. The vendor is unwilling to remediate, citing cost. The vendor contract includes a clause that requires adherence to security standards. The organization's risk appetite for third-party risk is low. What is the most appropriate risk response?

A.Avoid by terminating the contract
B.Mitigate by reducing data shared
C.Transfer via insurance
D.Accept the risk and monitor
AnswerA

With low third-party risk appetite and a contract clause mandating security standards, the vendor's refusal to remediate leaves the risk above tolerance. Terminating the contract eliminates the exposure entirely, which is avoidance — the only response that removes rather than accepts, transfers or mitigates the risk.

Why this answer

The vendor's refusal to remediate high-risk findings directly violates the contract's security standards clause, and the organization's low risk appetite for third-party risk means that accepting or mitigating the residual risk is unacceptable. Terminating the contract (avoidance) is the only response that eliminates the risk entirely, aligning with the principle that when a third party cannot or will not meet required security controls, the relationship should be severed to prevent potential data breaches or compliance violations.

Exam trap

The trap here is that candidates often choose mitigation (reducing data shared) because it seems like a compromise, but they overlook that the vendor's core data handling processes remain insecure, and the organization's low risk appetite demands complete elimination of the risk, not partial reduction.

How to eliminate wrong answers

Option B is wrong because reducing data shared (mitigation) does not address the vendor's unwillingness to remediate the root cause of the high-risk findings; the vendor's insecure data handling practices would still expose the organization to residual risk exceeding its low appetite. Option C is wrong because transferring risk via insurance does not reduce the likelihood or impact of a data breach; it only provides financial compensation after an incident, which is insufficient when the organization's risk appetite is low and the vendor is non-compliant with contractual security standards. Option D is wrong because accepting the risk and monitoring contradicts the organization's low risk appetite; acceptance is appropriate only when residual risk falls within appetite, but here the high-risk findings and vendor non-compliance create an unacceptable level of exposure.

27
MCQhard

A financial services firm is deploying a new trading platform. The risk committee has approved a risk treatment plan that includes a requirement to implement a circuit breaker that halts trading if losses exceed a predefined threshold. The project manager asks the risk practitioner to verify that the control is designed effectively before go-live. Which activity BEST validates the design of this risk mitigation control?

A.Monitor trading losses for the first month after go-live and confirm that the circuit breaker activates when the threshold is breached.
B.Confirm that the vendor's product documentation states the circuit breaker feature is included in the licensed version.
C.Ask the internal audit team to add the circuit breaker to the annual audit plan and review it during the next audit cycle.
D.Review the control's technical specification and conduct a tabletop walkthrough with the trading and technology teams.
AnswerD

Design effectiveness is evaluated before the control operates in production. Reviewing the technical specification confirms that the circuit breaker logic matches the risk treatment requirement, and a tabletop walkthrough reveals whether the teams understand how the threshold triggers and who is responsible for halting trading. This combination validates the design without waiting for a live trading loss event.

Why this answer

Design effectiveness testing confirms that a control, as planned, will mitigate the identified risk before it is relied upon. Reviewing specifications and walking through scenarios with stakeholders validates the logic, thresholds, and responsibilities. Live monitoring tests operating effectiveness, internal audit provides later assurance, and vendor documentation only confirms feature availability.

The pre-go-live design validation is the most direct and timely way to confirm the circuit breaker will work as intended.

Exam trap

The trap here is confusing design effectiveness with operating effectiveness, and selecting live monitoring as the validation method.

28
MCQeasy

During a risk assessment, the risk owner identifies that the residual risk level is higher than the risk appetite. Which of the following actions should the risk owner take FIRST?

A.Update the risk register
B.Escalate to senior management
C.Implement additional controls
D.Reduce the risk appetite
AnswerB

Residual risk exceeding appetite sits outside the risk owner's delegated authority, so the owner cannot accept it unilaterally. Escalation to senior management is the required first step, since only they can authorise additional treatment or formally accept the elevated exposure.

Why this answer

When residual risk exceeds risk appetite, the risk owner must escalate to senior management because they have the authority to accept the risk or allocate resources for additional controls. This aligns with the CRISC framework's principle that risk acceptance decisions beyond appetite are a management responsibility, not the risk owner's alone.

Exam trap

The trap here is that candidates confuse the risk owner's authority with senior management's authority, assuming the risk owner can independently implement controls or adjust appetite without escalation.

How to eliminate wrong answers

Option A is wrong because updating the risk register is a documentation step that should occur after the decision is made, not the first action when risk exceeds appetite. Option C is wrong because implementing additional controls is a potential remediation step, but it requires senior management approval or direction first, as the risk owner cannot unilaterally decide to spend resources. Option D is wrong because reducing risk appetite is a strategic decision made by the board or senior management, not the risk owner, and changing appetite to match residual risk violates the purpose of having a defined appetite.

29
Multi-Selecteasy

Which TWO of the following are examples of risk mitigation controls?

Select 2 answers
A.Implementing a firewall
B.Purchasing cyber insurance
C.Accepting the risk
D.Encrypting sensitive data
E.Discontinuing a high-risk service
AnswersA, D

Mitigation reduces risk through preventive controls.

Why this answer

Implementing a firewall is a risk mitigation control because it reduces the likelihood and impact of unauthorized network access by enforcing access control policies based on source/destination IP addresses, ports, and protocols. Firewalls operate at Layers 3 and 4 (and sometimes Layer 7) of the OSI model to filter traffic, thereby directly reducing the attack surface and preventing exploitation of vulnerabilities.

Exam trap

The CRISC exam often tests the distinction between risk mitigation (reducing likelihood/impact) and risk transfer (e.g., insurance) or risk avoidance (e.g., discontinuing a service), so candidates mistakenly classify insurance or service discontinuation as mitigation when they are separate risk response strategies.

30
MCQhard

An organization uses a legacy system that cannot be patched because the vendor is defunct. The system supports a core business function. The risk assessment shows a high likelihood of exploitation and high impact. The board has decided to keep the system operational due to its criticality. Which risk response should the risk manager recommend?

A.Accept the risk
B.Implement compensating controls
C.Transfer via insurance
D.Avoid by decommissioning
AnswerB

Compensating controls reduce risk when patching is impossible, such as network segmentation, strict access controls or enhanced monitoring around the legacy system. This response accepts the system's continued operation while lowering likelihood or impact, matching the board's decision to retain it.

Why this answer

When a legacy system cannot be patched and the risk is high, compensating controls are the most appropriate response to reduce the residual risk to an acceptable level. Compensating controls, such as network segmentation, strict access controls, or an application-layer firewall, mitigate the exploitation vector without decommissioning the critical system. The board's decision to keep the system operational means avoidance is not an option, and acceptance alone would leave the organization exposed to an unacceptable risk level.

Exam trap

The trap here is that candidates often choose 'Accept the risk' because they misunderstand risk acceptance as a passive decision, but in CRISC, acceptance is only valid when the risk is within the risk appetite, not when the likelihood and impact are both high and the system is critical.

How to eliminate wrong answers

Option A is wrong because accepting the risk without any mitigation would leave the organization exposed to a high-likelihood, high-impact threat, which is typically unacceptable for a core business function; acceptance is only appropriate when the residual risk is within the organization's risk appetite. Option C is wrong because transferring via insurance does not reduce the likelihood or impact of a security incident; it only provides financial compensation after a loss, and for a legacy system with a high exploitation likelihood, the operational disruption and reputational damage are not fully transferable. Option D is wrong because avoiding by decommissioning contradicts the board's explicit decision to keep the system operational due to its criticality, and it would disrupt the core business function.

31
Multi-Selecteasy

A risk practitioner is reviewing the organization's risk response strategies for a high-value asset. Which TWO of the following are examples of risk mitigation techniques? (Choose two.)

Select 2 answers
A.Implementing firewalls to protect the network perimeter.
B.Conducting regular vulnerability assessments and patching.
C.Avoiding the risk by discontinuing the vulnerable activity.
D.Accepting the risk because the cost of mitigation exceeds the potential loss.
E.Purchasing cyber insurance to cover potential losses.
AnswersA, B

Correct: Firewalls reduce the likelihood of network-based attacks, which is a mitigation technique.

Why this answer

Implementing firewalls to protect the network perimeter is a risk mitigation technique because it reduces the likelihood of unauthorized access by filtering traffic based on security rules. Firewalls operate at layers 3 and 4 (and sometimes layer 7) of the OSI model, using stateful inspection or application-layer filtering to block malicious packets. This directly lowers the probability of a successful attack on the high-value asset, which is the essence of mitigation.

Exam trap

The trap here is that candidates often confuse risk mitigation with risk transfer (insurance) or risk acceptance, failing to recognize that mitigation involves active controls (like firewalls and patching) that reduce the risk level, not just financial compensation or inaction.

32
Drag & Dropmedium

Order the steps for implementing a risk treatment plan.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Risk treatment starts with selecting response, planning, approval, implementation, and monitoring.

33
MCQmedium

A software development company is adopting a DevOps model and wants to accelerate deployments. The risk manager is concerned that rapid changes could introduce security vulnerabilities. The team proposes implementing automated security testing in the CI/CD pipeline. Which of the following BEST describes the risk response strategy being applied?

A.Risk mitigation
B.Risk avoidance
C.Risk acceptance
D.Risk transfer
AnswerA

Automated security testing in the CI/CD pipeline is a mitigation control because it reduces the likelihood of security vulnerabilities being introduced into production. It addresses the risk by integrating security checks early and continuously, thus lowering the probability of a breach.

Why this answer

The correct answer is risk mitigation. By integrating automated security testing into the CI/CD pipeline, the company is implementing a control that reduces the likelihood of vulnerabilities reaching production. This is a proactive mitigation strategy that aligns with CRISC's emphasis on embedding risk management into business processes.

Exam trap

The trap here is thinking that adding security testing to a fast-paced process is avoidance or acceptance; it is mitigation because it reduces risk while allowing the business activity to continue.

34
MCQhard

A multinational bank has a risk appetite that allows for a maximum of 5% downtime for its online banking platform per quarter. The platform currently experiences 8% downtime due to frequent distributed denial-of-service (DDoS) attacks. The risk owner proposes investing in a cloud-based DDoS mitigation service. Which of the following should be the risk practitioner's PRIMARY consideration when evaluating this proposed risk response?

A.The total cost of the service compared to the potential financial losses from downtime.
B.The service provider's reputation and market share in the DDoS mitigation industry.
C.The expected reduction in downtime and whether it brings residual risk within the bank's risk appetite.
D.The service provider's ability to integrate with the bank's existing incident response plan.
AnswerC

The primary consideration is whether the proposed DDoS mitigation service will reduce the downtime from 8% to 5% or below, aligning with the bank's risk appetite. The risk practitioner must evaluate the control's effectiveness in mitigating the risk to an acceptable level. This involves analyzing the service's capabilities, historical performance, and any residual risk after implementation. Cost and integration are secondary to this fundamental risk-reduction assessment.

Why this answer

The risk practitioner's primary role is to evaluate whether a proposed risk response will bring residual risk within the organization's risk appetite. Here, the bank's risk appetite for downtime is 5%, but current downtime is 8%. The proposed DDoS mitigation service must be assessed for its ability to reduce downtime to 5% or less.

This assessment should consider the service's effectiveness, reliability, and any residual risk. Cost, integration, and vendor reputation are secondary factors that inform the decision but do not replace the core risk-reduction evaluation.

Exam trap

The trap here is prioritizing cost or vendor reputation over the fundamental question of whether the control actually reduces risk to within appetite.

35
MCQmedium

A hospital's risk register identifies that a critical medical imaging server runs an unsupported operating system, creating a high likelihood of exploitation. The vendor will not release a patch, and the server cannot be taken offline because it supports active patient care. The CISO asks the risk practitioner to reduce the likelihood of exploitation without disrupting imaging services. Which risk response is MOST appropriate?

A.Accept the risk because the server is essential to patient care and cannot be taken offline for replacement.
B.Isolate the imaging server on a dedicated network segment with strict firewall rules and deploy a host-based intrusion prevention system.
C.Avoid the risk by immediately decommissioning the imaging server and moving all imaging workloads to a cloud provider.
D.Transfer the risk by purchasing cyber insurance that covers medical device downtime and regulatory fines.
AnswerB

Compensating controls such as network segmentation and host-based IPS reduce the likelihood of exploitation while preserving availability for patient care. Because the vendor will not patch the unsupported OS, the risk practitioner must apply layered detective and preventive controls around the asset. This directly addresses the high likelihood of exploitation without requiring downtime or system replacement.

Why this answer

When a critical asset cannot be patched or replaced, compensating controls are the correct mitigation approach. Network segmentation limits lateral movement, and host-based IPS can detect and block exploitation attempts on the unsupported system. These measures reduce likelihood without requiring downtime, unlike acceptance, avoidance, or pure risk transfer, which do not address the technical vulnerability in this operational context.

Exam trap

The trap here is assuming that because the system is critical and cannot be replaced, the only remaining choice is to accept the risk.

36
MCQmedium

A healthcare organization has identified that its patient portal has a vulnerability that could expose sensitive data. The risk owner decides to implement multifactor authentication (MFA) for all users. After implementation, the risk practitioner conducts a follow-up assessment and finds that some users are sharing credentials, potentially bypassing MFA. The risk practitioner should FIRST:

A.Report the control failure to the risk owner and reassess the residual risk.
B.Recommend additional security awareness training for all users.
C.Implement technical controls to prevent credential sharing, such as device fingerprinting.
D.Accept the residual risk because MFA is still partially effective.
AnswerA

The risk practitioner's first step is to inform the risk owner that the implemented control (MFA) is not fully effective due to credential sharing. This triggers a reassessment of the residual risk, as the control may no longer reduce risk to an acceptable level. The practitioner should gather evidence, quantify the impact, and present findings to the risk owner so that a decision can be made on additional risk responses, such as stricter enforcement or alternative controls.

Why this answer

When a control is found to be ineffective or circumvented, the risk practitioner must first report the control failure to the risk owner and reassess the residual risk. This ensures that the risk owner is aware of the changed risk landscape and can make an informed decision on whether to accept, mitigate, or transfer the risk. The reassessment should consider the extent of credential sharing, its impact on the MFA control's effectiveness, and any additional vulnerabilities.

Only after this reassessment should further actions, such as training or technical controls, be considered.

Exam trap

The trap here is jumping to a solution like training or new controls without first reassessing the risk and informing the risk owner.

37
MCQmedium

A financial services firm's risk register shows that a critical trading application has a high inherent risk of unauthorized access. The risk owner decides to implement multifactor authentication (MFA) and role-based access controls (RBAC). After implementation, the residual risk score decreases but remains above the risk appetite. Which of the following should the risk practitioner recommend NEXT?

A.Perform additional risk response to further reduce the residual risk to within appetite.
B.Accept the residual risk because the controls have reduced it significantly.
C.Remove the existing controls and reassess the inherent risk.
D.Transfer the entire risk to a third party through insurance.
AnswerA

When residual risk remains above the risk appetite after implementing controls, the risk practitioner should recommend further risk response, such as additional controls, risk transfer, or avoidance. This aligns with the CRISC principle of continuous risk treatment until risk is within acceptable levels, ensuring alignment with organizational objectives.

Why this answer

The correct answer is to perform additional risk response because residual risk still exceeds the risk appetite. CRISC emphasizes that risk treatment is iterative: after controls are applied, if residual risk is not within appetite, further action is needed. This could include additional controls, risk avoidance, or transfer, but the key is to continue treatment until risk is acceptable.

Exam trap

The trap here is assuming that any reduction in risk after implementing controls is sufficient, even if residual risk remains above the risk appetite.

38
MCQmedium

A bank implements a new transaction monitoring system to detect fraudulent activities. After six months, the system has a high false positive rate, causing analysts to miss real threats. Which of the following is the BEST way to address this risk?

A.Accept the false positives as a cost of doing business
B.Tune the system to reduce false positives
C.Remove the monitoring system to focus on other controls
D.Hire additional analysts to review all alerts
AnswerB

Tuning thresholds and rules reduces false positives, restoring analyst capacity to investigate genuine alerts. This addresses the stated risk that excessive false positives cause real threats to be missed, rather than replacing or ignoring the monitoring system.

Why this answer

B is correct because tuning the system involves adjusting detection thresholds, rules, or machine learning models to reduce false positives while maintaining sensitivity to actual fraud. This directly addresses the root cause—poorly calibrated detection logic—without sacrificing the system's primary function or incurring unsustainable costs.

Exam trap

The trap here is that candidates may choose D (hire more analysts) because it seems like a direct solution to alert overload, but it fails to address the system's inefficiency and is not a sustainable risk response per CRISC principles.

How to eliminate wrong answers

Option A is wrong because accepting false positives as a cost of doing business ignores the operational risk that analysts miss real threats, leading to potential financial and regulatory damage. Option C is wrong because removing the monitoring system eliminates the primary detective control for fraud, leaving the bank exposed to undetected fraudulent transactions. Option D is wrong because hiring additional analysts does not fix the underlying system misconfiguration; it only masks the symptom with increased headcount, which is not scalable and still risks alert fatigue.

39
MCQmedium

During a review, a risk practitioner discovers that a key control for a high-risk process is not operating effectively. The risk owner is reluctant to invest in additional controls due to budget constraints. What should the risk practitioner do FIRST?

A.Accept the risk owner's decision
B.Document the deficiency and move on
C.Communicate the risk exposure to senior management
D.Escalate directly to the board
AnswerC

Escalating the exposure to senior management is the first step because the risk owner's budget refusal leaves the practitioner without authority to accept or fund the risk. Senior management owns risk acceptance at the organisational level, so they must decide whether to accept, mitigate or transfer the exposure.

Why this answer

The risk practitioner's primary duty is to ensure that senior management is aware of material risk exposures that could impact business objectives. When a key control for a high-risk process is ineffective and the risk owner refuses to remediate due to budget constraints, the practitioner must communicate the residual risk exposure to senior management, who have the authority to allocate resources and make strategic risk acceptance decisions. This aligns with the CRISC framework's emphasis on escalating risk information to the appropriate decision-making level when the risk owner's response is inadequate.

Exam trap

The trap here is that candidates confuse 'documenting the deficiency' (Option B) with completing the risk management process, but CRISC requires active communication of risk exposure to the appropriate authority, not just passive recording.

How to eliminate wrong answers

Option A is wrong because accepting the risk owner's decision without further action would violate the risk practitioner's responsibility to ensure that risk acceptance is based on complete and accurate information; the risk owner's budget-driven refusal does not constitute a valid risk acceptance decision without senior management's informed consent. Option B is wrong because simply documenting the deficiency and moving on fails to address the material risk exposure; documentation is necessary but not sufficient—the practitioner must actively communicate the risk to those who can authorize additional controls or formally accept the risk. Option D is wrong because escalating directly to the board bypasses the proper escalation chain; the board should only be involved for strategic-level risks or after senior management has been informed and has failed to act, not as a first step.

40
Matchingmedium

Match each risk response strategy to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Eliminate the activity that causes the risk

Reduce the likelihood or impact of the risk

Shift the risk to a third party, e.g., insurance

Acknowledge the risk and take no further action

Why these pairings

The correct matches are: Avoid – decision to not perform the activity; Accept – formal acceptance of risk; Mitigate – reduce likelihood/impact; Transfer – shift to another party. Common confusions include mixing transfer with avoidance and acceptance with mitigation.

41
MCQmedium

After implementing a new web application, the risk owner reports that the residual risk level is still above the risk appetite. Which of the following should be the risk practitioner's FIRST action?

A.Re-evaluate risk treatment options with the risk owner
B.Escalate directly to the board
C.Update the risk register to reflect the residual risk
D.Accept the residual risk
AnswerA

Residual risk exceeding appetite means the implemented treatment proved insufficient, so the practitioner must revisit treatment with the risk owner to identify additional or alternative controls. Re-evaluating options directly addresses the gap between current residual exposure and the defined appetite before escalation or acceptance is considered.

Why this answer

When residual risk remains above the risk appetite after treatment, the risk practitioner must first re-evaluate the existing risk treatment options with the risk owner. This collaborative review identifies whether additional controls (e.g., stricter input validation, rate limiting, or Web Application Firewall tuning) can further reduce the risk to an acceptable level before considering escalation or acceptance.

Exam trap

The trap here is that candidates often confuse the urgency of residual risk with the need to immediately escalate or accept it, when the correct first step is to revisit treatment options with the risk owner to see if further controls can close the gap.

How to eliminate wrong answers

Option B is wrong because escalating directly to the board bypasses the proper risk management process; the board should only be informed after all feasible treatment options have been exhausted and documented. Option C is wrong because updating the risk register to reflect residual risk is a documentation step that should occur after determining the final risk response, not as the first action. Option D is wrong because accepting residual risk above the risk appetite without first exploring additional mitigation measures violates the principle of risk reduction and could lead to unacceptable exposure.

42
MCQhard

A multinational corporation is deploying a new enterprise resource planning (ERP) system across 30 countries. The risk manager identifies that data residency laws in several countries require customer data to remain within national borders. The project team proposes using a single global cloud region for simplicity. Which risk response strategy is MOST appropriate for the risk manager to recommend?

A.Accept the risk because the cloud provider's global presence ensures compliance.
B.Mitigate the risk by implementing data localization controls, such as regional data centers or data residency zones.
C.Avoid the risk by canceling the ERP deployment in countries with strict data residency laws.
D.Transfer the risk by outsourcing data management to a third-party provider.
AnswerB

Mitigation through data localization controls directly addresses the legal requirement by ensuring data remains within required jurisdictions. This allows the ERP deployment to proceed while complying with laws. It is the most appropriate response because it reduces risk to an acceptable level without abandoning the business initiative.

Why this answer

The correct answer is to mitigate the risk by implementing data localization controls. This approach directly addresses the legal requirement while allowing the ERP deployment to continue. Risk mitigation is appropriate when the risk can be reduced to an acceptable level through controls, and it balances business needs with compliance obligations.

Exam trap

The trap here is assuming that using a global cloud region automatically satisfies data residency laws, or that transferring the risk to a third party absolves the organization of legal responsibility.

43
MCQeasy

A retail company has a risk register that includes a risk of inventory shrinkage due to employee theft. The risk manager decides to implement a new surveillance system and conduct background checks on all new hires. Which risk response strategy is being applied?

A.Risk avoidance
B.Risk acceptance
C.Risk transfer
D.Risk mitigation
AnswerD

Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. Surveillance systems deter theft and increase detection, while background checks reduce the likelihood of hiring individuals prone to theft. These actions directly lower the risk of inventory shrinkage, making this a clear example of mitigation.

Why this answer

Implementing surveillance and background checks are preventive controls that reduce the likelihood of employee theft. This is a classic risk mitigation strategy, as the company is taking direct action to lower the risk rather than accepting, avoiding, or transferring it. Mitigation is appropriate when the risk is significant and controls can cost-effectively reduce it.

Exam trap

The trap here is confusing mitigation with transfer, assuming that any action involving insurance or external parties is transfer, but these internal controls are clearly mitigation.

44
MCQmedium

An employee with access to sensitive financial data has been observed accessing systems outside of normal working hours and exhibiting erratic behavior. The IT risk manager suspects insider threat. What is the most appropriate risk response?

A.Terminate the employee immediately
B.Implement additional monitoring and restrictions
C.Accept the risk as the employee is trusted
D.Transfer via fidelity insurance
AnswerB

Insider threat involving privileged financial access cannot be proven immediately, so additional monitoring and restrictions contain the risk while evidence is gathered. This satisfies the need for a proportionate response that limits exposure without prematurely accusing or removing the employee.

Why this answer

Implementing additional monitoring and restrictions (Option B) is the most appropriate risk response because it allows the organization to gather more evidence of the suspected insider threat while immediately reducing the attack surface. This aligns with the risk mitigation strategy, as it directly addresses the observed anomalous behavior—accessing systems outside normal hours—without prematurely escalating the situation. In a financial data environment, this could involve enabling enhanced audit logging, restricting access to specific IP ranges or times, and deploying user and entity behavior analytics (UEBA) to detect deviations from baseline activity.

Exam trap

A common mistake in the CRISC exam is assuming that immediate termination (Option A) is the best response to insider threats, but the trap here is that termination is a punitive action, not a risk response—it fails to preserve evidence and may violate due process, whereas monitoring and restriction is a proper mitigation that balances security with operational continuity.

How to eliminate wrong answers

Option A is wrong because immediate termination without a full investigation could destroy critical forensic evidence, violate employment or data privacy laws, and does not address the root cause of the behavior; it is a reactive, punitive measure rather than a controlled risk response. Option C is wrong because accepting the risk based solely on the employee being 'trusted' ignores the clear indicators of potential malicious activity (erratic behavior, off-hours access) and violates the principle of least privilege and continuous monitoring required for sensitive financial data. Option D is wrong because transferring the risk via fidelity insurance only covers financial loss after an incident occurs, not the ongoing threat; it does nothing to prevent the insider from exfiltrating data or causing harm in the immediate term.

45
MCQmedium

A financial services company's risk register shows that a critical vulnerability in its online banking application has a high likelihood of exploitation and a high impact. The risk owner decides to implement a web application firewall (WAF) and conduct monthly penetration tests. Which risk response strategy is being applied?

A.Risk acceptance
B.Risk avoidance
C.Risk mitigation
D.Risk transfer
AnswerC

Risk mitigation reduces the likelihood or impact of a risk through controls. Implementing a WAF and conducting penetration tests are detective and preventive controls that lower the probability of exploitation and the potential damage, aligning with mitigation.

Why this answer

The organization is reducing the likelihood and impact of the vulnerability by adding a WAF and performing regular penetration tests. These actions are classic risk mitigation controls that lower residual risk. Avoidance would mean discontinuing the online banking service, transfer would involve insurance, and acceptance would mean no action.

Exam trap

The trap here is confusing mitigation with avoidance because both involve taking action, but avoidance eliminates the risk source entirely.

46
Multi-Selectmedium

Which TWO of the following are examples of risk avoidance? (Select TWO.)

Select 2 answers
A.Accepting the risk
B.Installing a firewall
C.Deciding not to enter a new market
D.Purchasing insurance
E.Discontinuing a risky product line
AnswersC, E

Declining to enter a new market eliminates the exposure entirely rather than reducing or transferring it, satisfying the stem's requirement for risk avoidance. Unlike mitigation, which lowers likelihood or impact, or acceptance, which retains the risk, avoidance removes the underlying activity generating the threat.

Why this answer

Risk avoidance involves taking action to eliminate the risk entirely by not engaging in the activity that introduces it. Option C, 'Deciding not to enter a new market,' avoids all associated market, regulatory, and competitive risks by simply not pursuing that business opportunity. Option E, 'Discontinuing a risky product line,' removes the risk by ceasing the activity that generates it, such as halting production of a product with known safety or compliance issues.

Exam trap

The trap here is that candidates often confuse risk avoidance with risk mitigation or transfer, mistakenly selecting options like 'installing a firewall' (mitigation) or 'purchasing insurance' (transfer) as examples of avoidance, when avoidance requires ceasing or not starting the risk-generating activity.

47
MCQmedium

A risk practitioner is reviewing the organization's risk register and notes that a critical web application has a high inherent risk of SQL injection. The development team proposes implementing a web application firewall (WAF) with virtual patching. The risk practitioner's primary responsibility in this scenario is to:

A.Immediately implement the WAF and virtual patching to address the vulnerability before any exploitation occurs.
B.Transfer the risk by purchasing cyber insurance that covers SQL injection attacks, since the WAF may not be fully effective.
C.Accept the risk because the WAF will eventually be deployed and the residual risk will be managed by the IT team.
D.Evaluate whether the proposed control reduces risk to an acceptable level within the organization's risk appetite.
AnswerD

The risk practitioner's role is to assess whether the proposed risk response (WAF with virtual patching) effectively mitigates the identified risk to a level that aligns with the organization's risk appetite. This involves analyzing the control's expected effectiveness, cost, and impact on residual risk. The practitioner does not implement controls or accept risk unilaterally; rather, they provide guidance to ensure the response is appropriate and aligned with business objectives.

Why this answer

The risk practitioner's core duty is to evaluate risk responses, not to implement them or accept risk. In this scenario, the proposed WAF with virtual patching is a mitigation control. The practitioner must assess whether it reduces the SQL injection risk to a level consistent with the organization's risk appetite.

This involves considering control effectiveness, potential residual risk, and cost-benefit. Only after this evaluation can the risk owner make an informed decision.

Exam trap

The trap here is confusing the risk practitioner's advisory role with hands-on implementation or risk acceptance authority.

48
MCQeasy

An organization decides to outsource its data center operations to a third party. This is an example of which risk response?

A.Risk reduction
B.Risk transfer
C.Risk acceptance
D.Risk avoidance
AnswerB

Outsourcing shifts the financial impact of data centre failures to the third party, satisfying the stem's need to reallocate risk ownership. Unlike risk avoidance, which eliminates the activity, or mitigation, which reduces likelihood, transfer moves the consequence to another party via contract.

Why this answer

Outsourcing data center operations transfers the financial and operational risks associated with managing the infrastructure to a third-party provider. This is a classic risk transfer response because the organization retains ownership of the data and business accountability but shifts the liability for physical security, hardware maintenance, and uptime to the vendor via contractual agreements, such as SLAs with penalty clauses.

Exam trap

The trap here is that candidates confuse risk transfer with risk reduction, mistakenly thinking that outsourcing reduces the risk of hardware failure, when in fact it only shifts the financial liability for that failure, not the operational impact on the business.

How to eliminate wrong answers

Option A is wrong because risk reduction involves implementing controls to lower the likelihood or impact of a risk, such as deploying redundant power supplies or fire suppression systems, not outsourcing operations. Option C is wrong because risk acceptance means formally acknowledging the risk and choosing to bear it without additional action, which contradicts the active decision to engage a third party. Option D is wrong because risk avoidance would mean ceasing the activity that generates the risk, such as shutting down the data center entirely, rather than transferring its management to another entity.

49
MCQeasy

A risk practitioner is reviewing the organization's risk response plan for a database containing personally identifiable information (PII). The plan states that the database will be encrypted at rest, access will be restricted to authorized personnel, and regular backups will be performed. Which risk response strategy is being applied?

A.Risk mitigation
B.Risk transfer
C.Risk avoidance
D.Risk acceptance
AnswerA

The plan includes encryption, access restrictions, and backups, all of which are controls designed to reduce the likelihood and impact of a data breach. These actions are characteristic of risk mitigation, where the organization takes steps to lower risk to an acceptable level while continuing the business activity. The strategy is clearly mitigation.

Why this answer

Implementing encryption, access controls, and backups are all mitigation actions that reduce the likelihood or impact of a breach. The organization is actively managing the risk rather than avoiding, transferring, or accepting it. Therefore, the risk response strategy is mitigation.

Exam trap

The trap here is overthinking and selecting risk transfer because backups might seem like insurance, but they are actually a mitigation control.

50
MCQmedium

A financial services firm has a critical web application that must remain available 24/7. The risk assessment indicates that a distributed denial-of-service (DDoS) attack could cause significant downtime. The risk owner decides to implement a cloud-based DDoS mitigation service that scrubs traffic before it reaches the application. Which risk response strategy does this represent?

A.Risk avoidance
B.Risk acceptance
C.Risk transference
D.Risk mitigation
AnswerD

Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. By deploying a cloud-based DDoS mitigation service, the firm adds a control that scrubs malicious traffic, thereby reducing the chance of downtime and lessening the impact of an attack. This aligns with the definition of risk mitigation, as the risk is still present but its effect is diminished.

Why this answer

Implementing a DDoS mitigation service is a classic example of risk mitigation because it reduces the likelihood or impact of a threat. The risk is not avoided (the service continues), not transferred (the firm retains responsibility), and not accepted (action is taken). Mitigation controls are designed to bring residual risk within the organization's risk appetite.

Exam trap

The trap here is confusing the use of a third-party service with risk transference, when in fact the service is a mitigation control that reduces risk.

51
MCQmedium

A financial services firm has identified that its primary data center is located in a region prone to hurricanes. The risk manager proposes purchasing business interruption insurance to cover potential losses from a catastrophic event. Which risk response strategy does this represent?

A.Risk avoidance
B.Risk acceptance
C.Risk transfer
D.Risk mitigation
AnswerC

Risk transfer shifts the financial consequences of a risk to a third party, typically through insurance or outsourcing. By purchasing business interruption insurance, the firm transfers the financial loss from a hurricane to the insurer. The risk itself remains, but the financial impact is borne by another party, making this the correct classification.

Why this answer

Purchasing insurance is a classic example of risk transfer, where the financial impact of a risk is shifted to an insurance provider. The risk event (hurricane) still occurs, but the firm is compensated for losses, protecting its financial stability. This strategy is appropriate when the risk is high-impact but low-frequency, and the cost of insurance is justified.

Exam trap

The trap here is confusing risk transfer with risk mitigation, assuming that buying insurance reduces the risk itself rather than just its financial consequences.

52
MCQhard

A risk manager is reviewing the organization's risk treatment plan for a critical web application. The plan includes implementing a web application firewall (WAF), conducting regular penetration tests, and purchasing cyber insurance. The risk manager notes that the residual risk after these treatments is still above the risk appetite. According to CRISC, what should the risk manager do NEXT?

A.Reassess the risk to ensure the risk assessment is accurate and adjust the risk score accordingly.
B.Update the risk register to reflect the residual risk and continue monitoring.
C.Implement additional controls immediately to reduce the residual risk to an acceptable level.
D.Escalate the residual risk to senior management for a decision on whether to accept, further treat, or avoid the risk.
AnswerD

When residual risk exceeds the risk appetite, it is outside the organization's tolerance. The risk manager should escalate to senior management, who have the authority to decide on further risk response, such as accepting the risk, implementing additional controls, or discontinuing the activity. This aligns with CRISC's emphasis on risk governance and ensuring risk is managed within appetite.

Why this answer

When residual risk exceeds the organization's risk appetite, it must be escalated to senior management, who are responsible for making risk-based decisions. They may choose to accept the risk, allocate resources for further mitigation, or avoid the activity. The risk manager's role is to inform and recommend, not to unilaterally decide or simply monitor.

Exam trap

The trap here is assuming the risk manager should automatically implement more controls, but without management's risk tolerance decision, that could be inappropriate or wasteful.

53
MCQmedium

An organization has a policy requiring all sensitive data to be encrypted at rest. During an audit, it is found that encryption keys are stored in plaintext on the same server. Which risk response is MOST appropriate?

A.Avoid by removing the data
B.Mitigate by encrypting the key file
C.Accept the risk because encryption is still applied
D.Transfer the risk to a cloud provider
AnswerB

Encrypting the keys protects them, reducing the risk of unauthorized decryption.

Why this answer

Storing encryption keys in plaintext on the same server as the encrypted data defeats the purpose of encryption, as an attacker who gains access to the server can easily decrypt the data. The most appropriate risk response is to mitigate by encrypting the key file itself, typically using a key-encryption key (KEK) or a hardware security module (HSM), which protects the keys even if the server is compromised. This directly addresses the vulnerability without removing the data or transferring the risk.

Exam trap

The trap here is that candidates mistakenly believe that simply having encryption applied (option C) is sufficient, overlooking the critical requirement that encryption keys must be protected separately from the data they encrypt—a fundamental principle of cryptographic security.

How to eliminate wrong answers

Option A is wrong because removing the data is an extreme measure that disrupts business operations and is unnecessary when a simpler, less costly mitigation (encrypting the key file) exists. Option C is wrong because accepting the risk ignores the fact that plaintext keys on the same server render the encryption ineffective, creating a high-likelihood, high-impact vulnerability that violates the organization's policy. Option D is wrong because transferring the risk to a cloud provider does not inherently solve the problem—if the keys remain in plaintext on the same server, the same vulnerability persists regardless of who manages the infrastructure.

54
Drag & Dropmedium

Sequence the steps for implementing a new control based on risk assessment findings.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Control implementation involves design, procurement/build, testing, deployment, and monitoring.

55
MCQhard

Based on the exhibit, which risk is most likely present and what is the most appropriate risk response?

A.Risk of cost; set a budget alert
B.Risk of data exposure; apply a deny rule to restrict access
C.Risk of availability; implement backup
D.No risk; the policy is standard
AnswerB

The exposed storage configuration permits anonymous or over-broad access, creating data exposure risk. Applying a deny rule restricts that access, satisfying the stem's requirement for a response that directly removes the exposure path rather than merely detecting or transferring the risk.

Why this answer

The exhibit shows a cloud storage access policy that allows public access via a wildcard permission with an allow effect. This directly exposes data to the internet, creating a risk of unauthorized data exposure. The most appropriate risk response is to apply a deny rule to restrict access, such as modifying the policy to remove the wildcard permission or adding conditions to block public access.

Exam trap

The trap here is that candidates may confuse a permissive policy with a standard configuration, overlooking the severe security implication of a wildcard permission that allows public access.

How to eliminate wrong answers

Option A is wrong because the risk is not about cost; setting a budget alert does not address the security vulnerability of public data exposure. Option C is wrong because the risk is not about availability; implementing backup does not mitigate the unauthorized access risk. Option D is wrong because the policy is not standard; allowing public access via a wildcard principal is a well-known misconfiguration that violates the principle of least privilege.

56
Multi-Selectmedium

A retail company is launching a new mobile payment application. The risk practitioner is identifying risk response options for the risk of payment fraud. Which TWO of the following are examples of risk mitigation controls? (Choose two.)

Select 2 answers
A.Tokenization of payment card data
B.Implementing real-time fraud detection algorithms
C.Accepting the risk of fraud and monitoring it quarterly
D.Deciding not to offer mobile payments in certain countries
E.Purchasing cyber insurance to cover fraud losses
AnswersA, B

Tokenization replaces sensitive card data with non-sensitive tokens, reducing the impact of a data breach. It is a preventive control that mitigates the risk of payment fraud by making stolen tokens useless to attackers. This is a classic risk mitigation technique that reduces both likelihood and impact.

Why this answer

Tokenization and real-time fraud detection are both mitigation controls because they actively reduce the risk of payment fraud. Tokenization minimizes the value of stolen data, while fraud detection identifies and blocks suspicious transactions. The other options represent risk transfer, risk avoidance, and risk acceptance, which do not reduce the inherent risk.

Exam trap

The trap here is confusing risk transfer or avoidance with mitigation; controls that reduce likelihood or impact are mitigation, while insurance and avoidance are different strategies.

57
MCQhard

A company faces a risk of data loss due to untrained staff. They implement mandatory training and quarterly phishing simulations. This is:

A.Risk Avoidance
B.Risk Acceptance
C.Risk Mitigation
D.Risk Transfer
AnswerC

Training and phishing simulations reduce the likelihood of staff falling for attacks, lowering the risk's expected impact rather than avoiding, transferring or accepting it. The controls target the human cause directly, so the treatment is risk mitigation.

Why this answer

Mandatory training and quarterly phishing simulations are proactive controls that reduce the likelihood and impact of data loss from human error. This directly aligns with risk mitigation, which seeks to lower residual risk to an acceptable level without eliminating the activity or transferring the financial burden. The controls target the root cause (untrained staff) by improving security awareness and testing behavioral response.

Exam trap

The trap here is that candidates confuse 'risk mitigation' with 'risk avoidance' because they think training eliminates the risk entirely, but mitigation only reduces it, while avoidance would require stopping the use of email or data processing altogether.

How to eliminate wrong answers

Option A is wrong because risk avoidance would mean ceasing the activity that introduces the risk (e.g., not using email or not storing sensitive data), not training staff. Option B is wrong because risk acceptance involves acknowledging the risk and taking no action to reduce it, whereas the company is actively implementing controls. Option D is wrong because risk transfer shifts the financial impact to a third party (e.g., cyber insurance or outsourcing), not internal training and simulations.

58
MCQhard

A multinational corporation has a risk register entry for a supplier that provides critical components. The supplier has a history of financial instability, and the risk of supply chain disruption is high. The risk owner decides to dual-source the components from a second supplier. Which risk response strategy does this represent, and what is the primary benefit?

A.Risk transfer, because the risk is shared with the second supplier
B.Risk avoidance, because the organization avoids relying on a single supplier
C.Risk acceptance, because the organization accepts the supplier risk but adds a backup
D.Risk mitigation, because it reduces the likelihood of disruption
AnswerD

Dual-sourcing is a mitigation strategy that reduces the likelihood and impact of a supply chain disruption by ensuring an alternative source is available. It does not eliminate the risk but lowers the probability of a total shutdown if one supplier fails. This is a classic example of risk mitigation through redundancy and diversification.

Why this answer

Dual-sourcing is a risk mitigation technique that reduces the likelihood of supply chain disruption by providing an alternative source. It does not transfer, avoid, or accept the risk; it actively reduces it. The primary benefit is increased resilience and reduced dependency on a single supplier.

Exam trap

The trap here is confusing dual-sourcing with risk transfer because a second supplier is involved, but the risk is not shifted financially.

59
MCQeasy

For a risk with very low likelihood and low impact, what is the typical risk response?

A.Mitigate
B.Transfer
C.Avoid
D.Accept
AnswerD

Acceptance suits risks whose likelihood and impact both sit at the lowest band, where treatment cost exceeds expected loss. The organisation retains the risk knowingly, monitors it, and allocates no further controls, which is proportionate given the negligible exposure.

Why this answer

When a risk has very low likelihood and low impact, the cost of implementing controls (mitigation, transfer, or avoidance) typically exceeds the potential loss. Accepting the risk is the most cost-effective response, as it acknowledges the residual risk without active treatment. This aligns with the principle that risk acceptance is appropriate for risks below the organization's risk appetite threshold.

Exam trap

The trap here is that candidates mistakenly apply mitigation or transfer to all risks, failing to recognize that acceptance is the default response for low-likelihood, low-impact risks where the cost of treatment exceeds the potential loss.

How to eliminate wrong answers

Option A is wrong because mitigation involves reducing likelihood or impact through controls, which is unnecessary and wasteful for a risk with negligible potential loss. Option B is wrong because transfer (e.g., insurance or outsourcing) incurs premium costs or contractual overhead that outweighs the trivial exposure. Option C is wrong because avoidance (e.g., discontinuing the activity) would eliminate a low-value risk at the cost of losing business functionality or opportunity, which is disproportionate.

60
MCQmedium

A software development company is launching a new mobile application that will collect user location data. The risk manager identifies that the data collection could violate privacy regulations if not properly disclosed. The legal team recommends updating the privacy policy and obtaining explicit user consent. Which risk response strategy is this?

A.Risk avoidance
B.Risk transfer
C.Risk acceptance
D.Risk mitigation
AnswerD

Updating the privacy policy and obtaining explicit consent are controls that reduce the likelihood of privacy violations and regulatory fines. These actions mitigate the risk by ensuring transparency and user agreement, aligning with legal requirements. Therefore, this is a risk mitigation strategy, as the company is actively reducing the risk's potential impact.

Why this answer

By updating the privacy policy and obtaining explicit consent, the company is implementing controls to reduce the likelihood of privacy violations. This is a mitigation strategy because it addresses the risk directly through compliance measures. Avoidance would mean not collecting data, transfer would involve shifting liability, and acceptance would mean doing nothing.

Exam trap

The trap here is thinking that compliance actions are avoidance because they follow regulations, but they are actually mitigation since the risky activity continues with added controls.

61
MCQmedium

A global company uses a critical third-party vendor for data processing. The inherent risk is high, but the vendor has implemented robust controls. However, due to recent geopolitical instability, the vendor's physical location is at risk. The risk owner recommends purchasing a business continuity insurance policy. Which risk response is being applied?

A.Transfer
B.Avoid
C.Accept
D.Mitigate
AnswerA

Purchasing insurance shifts the financial consequence of a disruption to an insurer, which is the defining characteristic of risk transfer. The vendor's location risk remains, but its monetary impact moves elsewhere, satisfying the stem's description of the risk owner's chosen response.

Why this answer

Purchasing a business continuity insurance policy transfers the financial impact of the risk to a third party (the insurer), which is the definition of the transfer response. The vendor's robust controls address some risk, but the geopolitical risk remains and is being shifted via insurance. This is a classic example of risk transfer through insurance.

Exam trap

CRISC often tests the difference between transfer and mitigate, so candidates may pick mitigate because controls are mentioned, but the specific action of buying insurance is transfer.

How to eliminate wrong answers

Option B is wrong because avoidance would mean eliminating the activity or vendor relationship entirely, which is not happening here. Option C is wrong because acceptance means acknowledging the risk and taking no action (or establishing a contingency), whereas here a specific action (buying insurance) is taken. Option D is wrong because mitigation reduces the probability or impact through controls, but the action described is financial risk transfer, not control implementation.

62
Multi-Selecteasy

Which THREE of the following are examples of risk mitigation controls? (Select THREE.)

Select 3 answers
A.Firewall
B.Outsourcing IT helpdesk
C.Encryption
D.Security awareness training
E.Cyber insurance
AnswersA, C, D

Firewalls reduce the likelihood of network attacks.

Why this answer

A firewall is a risk mitigation control because it enforces network security policies by filtering traffic based on rules, thereby reducing the likelihood of unauthorized access or attacks. It directly reduces the probability of a threat exploiting a vulnerability, which is the essence of mitigation.

Exam trap

The trap here is confusing risk mitigation (which reduces likelihood or impact) with risk transfer (which shifts the financial burden to another party), leading candidates to incorrectly select outsourcing or insurance as mitigation controls.

63
MCQhard

You are a risk practitioner at a financial institution that is migrating its core banking system to a cloud provider. The migration plan includes a phased approach, with the first phase moving non-critical applications. However, during the second phase (moving customer-facing applications), the cloud provider experiences a major outage that lasts 6 hours. The outage was caused by a misconfiguration in the provider's network. The institution had conducted a risk assessment and identified cloud provider downtime as a risk, but the treatment plan only included a service level agreement (SLA) with financial penalties. The SLA does not cover the reputational damage and loss of customer trust. The risk register shows that the residual risk level was marked as 'low' before the incident. After the incident, senior management is demanding a review. Which of the following is the MOST appropriate action for the risk practitioner to take?

A.Negotiate a higher penalty in the SLA
B.Initiate a legal claim against the provider
C.Update the risk register to reflect the incident and accept the residual risk
D.Reassess the risk and recommend implementing a multi-cloud architecture for critical applications
AnswerD

The SLA-only treatment failed to address reputational and trust losses, so residual risk was misrated as low. Reassessing and recommending multi-cloud architecture for critical applications removes single-provider dependency, directly addressing the concentration risk the outage exposed and satisfying management's demand for a revised treatment.

Why this answer

The incident revealed that the existing risk treatment (SLA financial penalties) was insufficient to address the actual impact (reputational damage and loss of customer trust). The risk practitioner must reassess the risk with the new information and recommend a more robust mitigation strategy, such as multi-cloud architecture, to reduce the likelihood or impact of a single provider's outage affecting critical customer-facing applications.

Exam trap

The trap here is that candidates may think updating the risk register (Option C) is sufficient, but CRISC emphasizes that after a risk materializes with greater impact than assessed, the risk must be reassessed and the treatment plan revised, not just documented.

How to eliminate wrong answers

Option A is wrong because negotiating a higher penalty in the SLA still does not address the unmitigated reputational damage and loss of customer trust; financial penalties compensate for direct costs but not intangible impacts. Option B is wrong because initiating a legal claim is a reactive, punitive measure that does not improve future resilience and may be precluded by the SLA's limitation of liability clauses. Option C is wrong because simply updating the risk register to reflect the incident and accepting the residual risk ignores the need to reassess and improve controls after a realized risk that exceeded the accepted level.

64
Multi-Selecthard

A multinational corporation is developing a risk treatment plan for a newly identified risk: a critical vendor's financial instability could disrupt the supply chain. The risk manager is considering several options. Which TWO of the following are examples of risk mitigation controls that directly reduce the likelihood or impact of this risk? (Choose two.)

Select 2 answers
A.Accepting the risk and documenting it in the risk register
B.Purchasing supply chain insurance to cover losses from vendor failure
C.Requiring the vendor to provide audited financial statements quarterly
D.Transferring the risk to the vendor via a contract clause
E.Qualifying a second supplier for critical components
AnswersC, E

Monitoring the vendor's financial health through audited statements enables early detection of instability, allowing the organization to take proactive measures. This reduces the likelihood of unexpected disruption by providing time to find alternatives or adjust contracts. It is a mitigation control that addresses the risk's likelihood through ongoing monitoring.

Why this answer

Qualifying a second supplier and requiring audited financial statements are both mitigation controls. The second supplier reduces impact by providing redundancy, while financial monitoring reduces likelihood by enabling early intervention. Insurance and contract clauses transfer risk, and acceptance does nothing to reduce it, so they are not mitigation.

Exam trap

The trap here is confusing risk transfer with mitigation, assuming that any action involving contracts or insurance reduces risk, but transfer only shifts financial consequences.

65
Multi-Selectmedium

A retail company is implementing a new point-of-sale (POS) system that accepts contactless payments. The risk practitioner identifies that the existing network segmentation between the POS environment and the corporate network is inadequate. The risk committee asks for compensating controls that will reduce the risk of lateral movement from a compromised POS terminal. Which TWO of the following controls BEST address this risk? (Choose two.)

Select 2 answers
A.Store payment card data in a centralized encrypted database on the corporate network to simplify management.
B.Implement network access control (NAC) that requires POS terminals to authenticate and comply with a hardened configuration before joining the network.
C.Enable full disk encryption on all POS terminals to protect payment card data at rest.
D.Deploy a next-generation firewall between the POS network and the corporate network with rules that deny all traffic except required payment processor endpoints.
E.Conduct quarterly vulnerability scans of the POS environment to identify missing patches.
AnswersB, D

Network access control ensures that only compliant, authenticated POS devices can connect to the network. This reduces the likelihood that a compromised or unauthorized device can establish a foothold and move laterally. By enforcing hardened configurations and device identity, NAC acts as a preventive control that complements segmentation and directly addresses the risk of lateral movement from a compromised terminal.

Why this answer

Lateral movement from a compromised POS terminal is best mitigated by preventive controls that restrict network traffic and enforce device trust. A next-generation firewall with least-privilege rules limits what the POS network can reach, and network access control ensures only compliant, authenticated devices connect. Together they compensate for weak segmentation by reducing the pathways and trust an attacker can exploit.

Encryption, scanning, and centralization do not directly block lateral movement.

Exam trap

The trap here is selecting data protection controls like encryption or detective controls like scanning when the risk is specifically about network lateral movement.

66
MCQhard

A financial services firm has a risk register entry for a critical trading application. The business owner proposes adding a redundant data center to reduce downtime risk. The risk practitioner notes that the redundancy will cost $2 million annually and reduce expected annual loss from $3 million to $500,000. Which factor is MOST important for the risk practitioner to evaluate before recommending approval?

A.Whether the redundant data center will eliminate all downtime risk for the trading application.
B.Whether the business owner has the authority to approve the $2 million annual expenditure.
C.Whether the redundant data center aligns with the firm's risk appetite and tolerance.
D.Whether the $2 million annual cost is lower than the $3 million expected annual loss.
AnswerC

Risk response decisions must be evaluated against the organization's risk appetite and tolerance. Even if the control is cost-effective, it should not be recommended if it pushes residual risk below tolerance in a way that misallocates resources, or if the business is unwilling to accept the operational complexity. Alignment with appetite ensures the response is appropriate for the firm's objectives and governance.

Why this answer

Before recommending a risk response, the practitioner must confirm alignment with the organization's risk appetite and tolerance. The cost-benefit analysis supports the redundancy, but appetite alignment ensures the response is consistent with governance and strategic objectives. Evaluating appetite and tolerance is the overarching criterion that determines whether a control is appropriate, not merely whether it is affordable or technically feasible.

Exam trap

The trap here is fixating on the cost-benefit arithmetic and overlooking that risk appetite and tolerance are the governing criteria for response selection.

67
MCQhard

A financial institution is implementing a new online banking platform. The risk assessment identified that the platform will handle sensitive customer data and must comply with GDPR and local banking regulations. The project team proposes encrypting all data at rest and in transit, implementing multi-factor authentication (MFA), and conducting quarterly penetration tests. However, the risk owner is concerned about the residual risk of a sophisticated phishing attack that could bypass MFA. The board has a low risk appetite. What is the BEST way to address this residual risk?

A.Purchase cyber insurance to transfer the financial impact of a potential phishing attack.
B.Implement advanced phishing-resistant MFA (e.g., FIDO2) and conduct regular employee phishing simulation training.
C.Reduce the project scope to exclude online banking and revert to a less risky channel.
D.Accept the residual risk because the existing controls (encryption, MFA, pen tests) already provide reasonable assurance.
AnswerB

Phishing-resistant MFA such as FIDO2 uses origin-bound cryptographic credentials that cannot be replayed by proxy phishing sites, directly mitigating the MFA-bypass residual risk. Combining it with simulation training addresses the human factor, aligning treatment with the board's low risk appetite.

Why this answer

The residual risk is a sophisticated phishing attack that could bypass MFA, and the board has a low risk appetite, so the risk must be reduced rather than transferred or accepted. Implementing phishing-resistant MFA such as FIDO2/WebAuthn (hardware security keys or passkeys) removes the shared-secret and OTP weaknesses that phishing kits exploit, and pairing it with ongoing phishing simulation training hardens the human layer. This directly addresses the specific residual risk while preserving the business value of the online banking platform.

Exam trap

CRISC often tests the distinction between risk response types (avoid, mitigate, transfer, accept) — candidates pick insurance (transfer) or acceptance because they sound pragmatic, but a low risk appetite plus an identified residual risk demands a mitigation answer that reduces likelihood, not one that merely moves or tolerates the impact.

How to eliminate wrong answers

Option A is wrong because cyber insurance only transfers the financial consequence of a phishing loss; it does not reduce the likelihood of the attack and leaves the low-appetite board exposed to the underlying risk. Option C is wrong because reducing scope to exclude online banking is a risk-avoidance overreaction that destroys business value when a targeted control (phishing-resistant MFA) can bring the risk within appetite. Option D is wrong because accepting the residual risk contradicts the board's stated low risk appetite, and standard MFA plus pen tests do not mitigate real-time adversary-in-the-middle phishing that defeats OTP-based MFA.

68
MCQeasy

A new privacy regulation requires that all personal data be encrypted at rest. The current systems lack encryption. The cost to implement encryption is moderate, and the risk of non-compliance is high. Which risk response is most appropriate?

A.Mitigate by implementing encryption
B.Accept the risk
C.Avoid by discontinuing data processing
D.Transfer via cyber insurance
AnswerA

Implementing encryption directly removes the regulatory exposure, satisfying the requirement that personal data be encrypted at rest. With moderate cost against high non-compliance risk, mitigation offers the best value; acceptance, avoidance or transfer would leave the legal obligation unmet. Encryption is the precise control the regulation mandates.

Why this answer

Mitigating the risk by implementing encryption is the most appropriate response because the cost is moderate and the risk of non-compliance is high. Encryption directly addresses the regulatory requirement and reduces the risk to an acceptable level. This aligns with risk management principles where high-impact risks with feasible controls should be mitigated.

Exam trap

CRISC often tests the misconception that transferring risk via insurance is sufficient for compliance, or that acceptance is viable when the risk is high; candidates must recognize that mitigation is the correct response when the cost is reasonable and the risk is significant.

How to eliminate wrong answers

Option B is wrong because accepting the risk is inappropriate when non-compliance carries high penalties and the cost to mitigate is moderate; acceptance is only suitable for low-impact risks or when mitigation is too costly. Option C is wrong because avoiding the risk by discontinuing data processing would likely disrupt business operations and is not proportionate to the moderate cost of encryption. Option D is wrong because transferring the risk via cyber insurance does not address the regulatory requirement for encryption at rest; insurance may cover financial losses but does not achieve compliance.

69
MCQeasy

A retail company's risk register shows that a point-of-sale system vulnerability has a high likelihood and high impact. The IT team proposes applying a vendor patch, but the patch has not been tested with the custom payment application. Which risk response strategy is being considered?

A.Risk transfer
B.Risk acceptance
C.Risk mitigation
D.Risk avoidance
AnswerC

Mitigation involves implementing controls to reduce the likelihood or impact of a risk. Applying a vendor patch directly reduces the likelihood of exploitation of the POS vulnerability. The fact that the patch is untested with the custom application introduces a new risk, but the intended response strategy remains mitigation because the goal is to lower the original risk.

Why this answer

The IT team is proposing a patch to reduce the likelihood of exploitation, which is a mitigation response. Mitigation is the appropriate strategy when an organization chooses to implement controls to lower risk rather than accept, transfer, or avoid it. The untested patch introduces a secondary risk that must be managed, but the primary response strategy remains mitigation.

Exam trap

The trap here is confusing mitigation with acceptance because the patch is untested, but the intent to reduce risk through a control defines mitigation.

70
MCQhard

A multinational organization is implementing a risk mitigation strategy for a critical system. The business impact analysis shows that downtime costs are extremely high. Which risk response strategy is MOST appropriate for this scenario?

A.Risk avoidance by decommissioning the system
B.Risk transfer through cyber insurance
C.Risk reduction by implementing redundant systems
D.Risk acceptance because mitigation is too costly
AnswerC

Redundant systems directly address the extreme downtime cost identified in the business impact analysis by eliminating single points of failure. Failover to a standby component maintains availability during hardware or service faults, reducing the probability and duration of outages. This satisfies the mitigation objective where downtime losses outweigh the cost of duplicate infrastructure.

Why this answer

Given the extremely high downtime costs, the most appropriate risk response is risk reduction through implementing redundant systems. This directly addresses the critical system's availability requirement by eliminating single points of failure, thereby reducing both the likelihood and impact of downtime. Decommissioning the system (avoidance) would eliminate the business function entirely, which is typically not viable for a critical system, while insurance (transfer) only provides financial compensation after the loss, not preventing the operational impact of downtime.

Exam trap

The trap here is that candidates may confuse risk transfer (insurance) as a primary solution for high downtime costs, overlooking that insurance does not prevent the operational impact and lost revenue during the outage itself, which is the core concern in this scenario.

How to eliminate wrong answers

Option A is wrong because risk avoidance by decommissioning the system would eliminate the business function that the critical system supports, which is typically not a viable strategy for a system deemed critical to operations. Option B is wrong because risk transfer through cyber insurance only provides financial reimbursement after a loss event, but does not prevent the extremely high operational downtime costs or the associated business disruption. Option D is wrong because risk acceptance is inappropriate when the business impact analysis shows that downtime costs are extremely high and a cost-effective mitigation (like redundancy) is available.

71
Multi-Selecthard

Which THREE of the following are key components of an effective risk treatment plan?

Select 3 answers
A.Assigned responsibilities
B.Risk acceptance criteria
C.A timeline for implementation
D.The risk owner's signature
E.A detailed budget
AnswersA, B, C

Clear ownership ensures accountability.

Why this answer

Assigned responsibilities are a key component of an effective risk treatment plan because they ensure accountability for implementing specific risk mitigation actions. Without clear ownership, tasks may be delayed or overlooked, undermining the plan's execution. This aligns with the CRISC framework's emphasis on defining roles to operationalize risk response.

Exam trap

The trap here is that candidates confuse supporting artifacts (like budgets or signatures) with the core structural components of the plan, which are defined by ISACA as responsibilities, timelines, and acceptance criteria.

72
Drag & Dropmedium

Put the steps for performing a control self-assessment (CSA) in order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

CSA involves defining scope, identifying controls, assessing effectiveness, gap identification, and reporting.

73
Multi-Selecthard

A risk assessment identifies a high likelihood of a data breach due to insecure APIs. The risk team proposes disabling the APIs until they are secured, implementing a WAF, and purchasing breach insurance. Which THREE risk response options are being considered?

Select 3 answers
A.Remediate
B.Transfer
C.Avoid
D.Mitigate
E.Accept
AnswersB, C, D

Insurance transfers the financial impact.

Why this answer

(Transfer) is correct because purchasing breach insurance transfers the financial risk of a data breach to an insurance provider. Option C (Avoid) is correct because disabling the APIs until they are secured eliminates the risk entirely by removing the vulnerable component. Option D (Mitigate) is correct because implementing a Web Application Firewall (WAF) reduces the likelihood or impact of an API-based attack without removing the API.

Exam trap

A common trap in CRISC is confusing 'remediate' (fixing the root cause) with 'mitigate' (reducing risk without eliminating the cause). Implementing a WAF is a mitigation, not remediation, because the API remains vulnerable at its core.

74
MCQhard

A healthcare organization is required by regulation to retain patient records for seven years. The risk manager is evaluating a new cloud storage solution that offers encryption at rest but stores data in multiple jurisdictions. Which of the following is the MOST critical risk consideration when selecting this solution?

A.The encryption algorithm used by the cloud provider
B.The availability of the cloud service and its uptime guarantees
C.The physical security of the cloud provider's data centers
D.The legal and regulatory requirements for data residency in each jurisdiction
AnswerD

Healthcare data is subject to strict privacy laws that may prohibit storage in certain jurisdictions or require specific safeguards for cross-border transfers. Storing data in multiple jurisdictions could violate these laws, leading to fines and reputational damage. Therefore, understanding and complying with data residency requirements is the most critical risk consideration.

Why this answer

For a healthcare organization, regulatory compliance is paramount. Storing patient records in multiple jurisdictions can breach data residency laws, resulting in severe penalties. While encryption, physical security, and availability are relevant, they do not address the legal risk of unauthorized cross-border data storage.

The risk manager must prioritize compliance with data residency requirements before other technical controls.

Exam trap

The trap here is focusing on technical controls like encryption or physical security while overlooking the legal and regulatory implications of data residency, which can invalidate the entire solution.

75
MCQhard

A company is implementing a new cloud-based customer relationship management (CRM) system. The risk manager has identified that the vendor's security controls may not meet the company's requirements. Which of the following is the BEST way to address this risk?

A.Deny the existence of the risk
B.Purchase cyber insurance to cover potential losses
C.Avoid using the cloud CRM system
D.Include security requirements in the contract and perform regular vendor audits
AnswerD

Contractual security requirements establish enforceable vendor obligations, and regular audits verify ongoing compliance with those controls. This addresses the identified gap between the vendor's controls and the company's requirements through both preventive and detective measures.

Why this answer

The best way to address the risk that a vendor's security controls may not meet requirements is to include explicit security requirements in the contract and perform regular vendor audits. This contractual and assurance-based approach directly mitigates the risk by establishing enforceable obligations and ongoing verification. It aligns with risk management principles of treating risk through controls and monitoring rather than ignoring, transferring, or eliminating the business capability.

Exam trap

CRISC often tests the misconception that transferring risk via insurance is always the best answer, when in fact addressing the root cause through contractual controls and assurance is typically the preferred risk treatment.

How to eliminate wrong answers

Option A is wrong because denying the existence of a risk is not a valid risk response; it leaves the organization exposed and violates risk management fundamentals. Option B is wrong because purchasing cyber insurance transfers some financial impact but does not address the root cause of inadequate vendor security controls, and it does not ensure compliance with requirements. Option C is wrong because avoiding the cloud CRM system entirely may be an overreaction that eliminates business benefits; risk avoidance is only appropriate when the risk is unacceptable and no other treatment is feasible, which is not stated here.

Page 1 of 2 · 94 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Risk Response and Mitigation questions.