CRISC Risk Response and Reporting Practice Question
During a risk analysis, the risk team finds that a legacy inventory system has a single point of failure: one administrator holds the only credentials for the backup restoration process. The system supports regulatory filings with a hard deadline. Management proposes documenting the situation in the risk register and revisiting it next year. Which action should the risk practitioner take?
⚠ Common exam trap
The trap here is believing that logging a risk in the register and scheduling a future review constitutes an adequate risk response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate the concentration risk and recommend immediate interim controls such as credential escrow or a second trained administrator.
A single point of failure tied to a hard regulatory deadline and held by one person warrants prompt treatment, especially when low-cost interim measures exist. Escalating with a recommendation to escrow credentials or train a second administrator addresses availability and fraud exposure immediately while a permanent solution is designed. Deferring, blocking access, or relying solely on insurance leaves the operational and compliance risk intact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transfer the risk by purchasing additional cyber insurance for the inventory system.
Why it's wrong here
Insurance compensates financial loss but does not restore data or meet a regulatory filing deadline. If restoration fails, the organization still faces penalties, reputational damage, and operational disruption that a payout cannot fully offset. Transfer is a complement to, not a substitute for, reducing a concentration of credentials that threatens availability and integrity.
- ✗
Agree, because the risk is documented and the system still functions today.
Why it's wrong here
Documentation without treatment leaves a known single point of failure in place. The concentration of restoration credentials in one person creates both availability and fraud exposure, and the regulatory deadline magnifies the impact of any failure. Recording the risk does not reduce the likelihood that the administrator becomes unavailable or acts improperly, so agreeing to defer merely formalizes an unmanaged exposure.
- ✓
Escalate the concentration risk and recommend immediate interim controls such as credential escrow or a second trained administrator.
Why this is correct
The finding combines high impact with a low-cost remedy, which justifies prompt action rather than annual review. Credential escrow or a cross-trained backup administrator reduces both availability and integrity exposure quickly. Escalating also places the decision with the accountable owner, ensuring the regulatory deadline risk is weighed against the effort of remediation now.
- ✗
Remove the administrator's access until a permanent solution is approved.
Why it's wrong here
Revoking access without a replacement creates the very failure the analysis warns about, since no one could restore the system if an incident occurred. The goal is to reduce single-person dependency, not eliminate the only capable operator. A controlled transition, such as escrow credentials and train a second administrator, addresses the risk without introducing an immediate operational gap.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.