Courseiva

CRISC Risk Response and Reporting Practice Question

During a risk analysis, the risk team finds that a legacy inventory system has a single point of failure: one administrator holds the only credentials for the backup restoration process. The system supports regulatory filings with a hard deadline. Management proposes documenting the situation in the risk register and revisiting it next year. Which action should the risk practitioner take?

⚠ Common exam trap

The trap here is believing that logging a risk in the register and scheduling a future review constitutes an adequate risk response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Escalate the concentration risk and recommend immediate interim controls such as credential escrow or a second trained administrator.

A single point of failure tied to a hard regulatory deadline and held by one person warrants prompt treatment, especially when low-cost interim measures exist. Escalating with a recommendation to escrow credentials or train a second administrator addresses availability and fraud exposure immediately while a permanent solution is designed. Deferring, blocking access, or relying solely on insurance leaves the operational and compliance risk intact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Transfer the risk by purchasing additional cyber insurance for the inventory system.

    Why it's wrong here

    Insurance compensates financial loss but does not restore data or meet a regulatory filing deadline. If restoration fails, the organization still faces penalties, reputational damage, and operational disruption that a payout cannot fully offset. Transfer is a complement to, not a substitute for, reducing a concentration of credentials that threatens availability and integrity.

  • ✗

    Agree, because the risk is documented and the system still functions today.

    Why it's wrong here

    Documentation without treatment leaves a known single point of failure in place. The concentration of restoration credentials in one person creates both availability and fraud exposure, and the regulatory deadline magnifies the impact of any failure. Recording the risk does not reduce the likelihood that the administrator becomes unavailable or acts improperly, so agreeing to defer merely formalizes an unmanaged exposure.

  • ✓

    Escalate the concentration risk and recommend immediate interim controls such as credential escrow or a second trained administrator.

    Why this is correct

    The finding combines high impact with a low-cost remedy, which justifies prompt action rather than annual review. Credential escrow or a cross-trained backup administrator reduces both availability and integrity exposure quickly. Escalating also places the decision with the accountable owner, ensuring the regulatory deadline risk is weighed against the effort of remediation now.

  • ✗

    Remove the administrator's access until a permanent solution is approved.

    Why it's wrong here

    Revoking access without a replacement creates the very failure the analysis warns about, since no one could restore the system if an incident occurred. The goal is to reduce single-person dependency, not eliminate the only capable operator. A controlled transition, such as escrow credentials and train a second administrator, addresses the risk without introducing an immediate operational gap.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.