When to Accept Risk: A CRISC Case Study
Exhibit
Refer to the exhibit. ``` [Risk Register Excerpt] Risk ID: R-0042 Risk Description: Unauthorized access to customer PII due to weak database encryption Inherent Risk Score: 16 (Likelihood: 4, Impact: 4) Control: AES-256 encryption at rest (implemented) Residual Risk Score: 8 (Likelihood: 2, Impact: 4) Risk Appetite Threshold: 10 ```
Based on the risk register exhibit, which of the following is the MOST appropriate risk response for R-0042?
Quick Answer
The answer is to accept the risk and continue monitoring. This is the most appropriate response because R-0042 represents a low-likelihood, low-impact risk involving PII already protected by AES-256 encryption and strict access controls, meaning the residual risk falls well within the organization’s defined risk appetite. On the CRISC exam, this scenario tests your ability to distinguish when a risk is already so well-controlled that any further mitigation, transfer, or avoidance would introduce unnecessary cost or operational disruption—a classic example of risk acceptance in action. A common trap is assuming any PII risk must be mitigated or transferred, but the exam rewards recognizing that effective controls can make acceptance the leanest, most cost-efficient path. Memory tip: if the controls are already strong and the impact is low, “accept and monitor” is the logical song.
⚠ Common exam trap
A common mix-up: candidates assume any risk involving PII must be mitigated or avoided, ignoring the risk register's explicit low-likelihood and low-impact ratings and the existing strong controls, which make acceptance the most cost-effective and appropriate response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accept the risk and continue monitoring
R-0042 is a low-likelihood, low-impact risk involving PII stored with AES-256 encryption and strict access controls. The residual risk is within the organization's risk appetite, making acceptance with continued monitoring the most appropriate response. Mitigation, transfer, or avoidance would introduce unnecessary cost or operational disruption for a risk already well-controlled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mitigate the risk by implementing additional encryption controls
Why it's wrong here
Additional mitigation is not required because the risk is already within appetite.
- ✗
Transfer the risk to a third-party insurer
Why it's wrong here
Transfer is not necessary since the residual risk is within appetite.
- ✗
Avoid the risk by discontinuing storage of PII
Why it's wrong here
Avoidance is too drastic; the risk is acceptable.
- ✓
Accept the risk and continue monitoring
Why this is correct
Since residual risk is below the risk appetite threshold, acceptance is appropriate.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CRISC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company has identified a critical vulnerability in a legacy application that cannot be patched immediately. The application is used by a small number of users and supports a non-critical business process. Which of the following is the MOST appropriate risk response strategy?
easy- A.Avoidance
- B.Transfer
- ✓ C.Acceptance
- D.Mitigation
Why C: Acceptance is the most appropriate response because the vulnerability exists in a legacy application that supports a non-critical business process and is used by a small number of users. The cost and operational impact of patching or replacing the application outweigh the risk, making it acceptable to operate with the known vulnerability under formal risk acceptance.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.