Courseiva
Risk Response and MitigationhardMultiple ChoiceObjective-mapped

CRISC Risk Response and Mitigation Practice Question

GlobalTech Inc., a multinational corporation, is planning to migrate its customer data to a new cloud platform. The migration involves transferring sensitive personally identifiable information (PII) from an on-premises database to a cloud-based CRM. The risk manager conducted a risk assessment and identified several risks, including unauthorized access during transit and residual data exposure due to misconfiguration. Mitigation controls include encryption in transit, encryption at rest, and strict access controls. The residual risk after mitigation is assessed as medium. The risk appetite statement defines that 'No data breach incidents resulting in regulatory fines exceeding $1 million are acceptable.' The estimated potential fine from a breach is $5 million with a likelihood of 2% after controls. The cost of additional controls to reduce likelihood to 0.5% is $500,000. The migrating team proposes to purchase cyber insurance with a $3 million coverage for $200,000 annual premium. The board of directors prefers to accept the residual risk to avoid additional costs. What should the risk manager do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Advise the board to avoid the migration until all risks are eliminated.

The residual risk after mitigation still exceeds the risk appetite: the potential fine of $5 million exceeds the $1 million threshold, and neither the proposed insurance (which covers only $3 million and does not reduce the residual risk) nor additional controls (cost $500,000 to reduce likelihood to 0.5%, but the expected loss of $25,000 is still below $1 million? Actually, the expected loss after additional controls would be $5M * 0.5% = $25,000, which is within appetite; however, the board prefers to accept the residual risk, but the risk manager must align with the risk appetite statement. The board's preference conflicts with the risk appetite; therefore, the risk manager should advise avoidance (not migrate until risks are eliminated) as it is the only option that ensures no breach exceeds the $1M fine threshold. Options B and C leave the risk above appetite, and D is costly and may not fully eliminate the risk of a breach exceeding $1M, so avoidance is the most prudent choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Advise the board to avoid the migration until all risks are eliminated.

    Why this is correct

    Avoidance is the only response that satisfies the risk appetite.

  • Recommend purchasing cyber insurance to transfer the risk.

    Why it's wrong here

    Insurance coverage of $3 million leaves a residual impact of $2 million, still above appetite.

  • Accept the board's decision since the residual risk is medium.

    Why it's wrong here

    Acceptance violates the risk appetite.

  • Recommend implementing additional controls to reduce likelihood to 0.5%.

    Why it's wrong here

    Reducing likelihood does not lower the impact below $1 million.

About these practice questions

This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.