CRISC Information Technology and Security Practice Question
During the solution architecture review, the Architecture Review Board (ARB) identifies a security risk in a proposed cloud migration project. The solution relies on a single cloud region with no disaster recovery plan. Which of the following is the BEST recommendation to mitigate this risk?
⚠ Common exam trap
CRISC often tests the difference between risk mitigation, risk transfer, and risk assessment — candidates select insurance (transfer) or BIA (assessment) when the question asks for the BEST recommendation to mitigate an availability risk, which requires a preventive architectural control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy the application across multiple cloud regions with automated failover
The identified risk is the lack of disaster recovery for a single-region cloud deployment. The best mitigation is to deploy across multiple cloud regions with automated failover, which directly addresses the availability and resilience gap by ensuring the application survives a regional outage. This is a preventive/architectural control that reduces both likelihood and impact of downtime.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy the application across multiple cloud regions with automated failover
Why this is correct
Deploying across multiple cloud regions with automated failover directly removes the single-region dependency identified by the ARB, satisfying the resilience constraint the stem raises. Unlike backup-only or manual recovery approaches, automated failover maintains service availability during a regional outage, which is the specific risk the proposed architecture currently leaves unmitigated.
- ✗
Purchase cyber insurance to cover financial losses
Why it's wrong here
Cyber insurance transfers residual financial loss after an incident; it does not restore service or prevent the availability impact of a region outage. The risk here is loss of availability, which insurance cannot mitigate. Insurance is appropriate once technical controls are in place, as a financial backstop.
- ✗
Implement encryption at rest and in transit
Why it's wrong here
Encryption at rest and in transit protects data confidentiality, but does nothing to address the loss of availability from a single-region failure with no recovery capability. Multi-region deployment with a documented disaster recovery plan is required; encryption is the right control for data-exposure risk, not resilience.
- ✗
Conduct a business impact analysis (BIA)
Why it's wrong here
A business impact analysis identifies critical processes and recovery requirements; it produces information, not a control, so it leaves the single-region exposure unchanged. It is tempting because a BIA normally precedes disaster recovery planning. The ARB needs a mitigating recommendation, such as multi-region failover with a tested DR plan.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.