Courseiva
mediumMultiple Choice

Selecting the Right Risk Response: Mitigation When Controls Are Effective

During a risk assessment, an organization identifies that its primary data center is located in a flood-prone area. Which risk treatment option would best address this risk?

⚠ Common exam trap

Many candidates confuse risk transfer (insurance) with risk mitigation, failing to recognize that insurance does not prevent operational downtime or data loss, whereas physical controls directly reduce the risk's likelihood and impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement flood barriers and redundant cooling systems

Implementing flood barriers and redundant cooling systems directly reduces the likelihood and impact of a flood event on the data center's physical infrastructure. This is a risk mitigation strategy that proactively addresses the root cause of the risk (flooding) by hardening the facility, which is the most effective treatment for a high-probability, high-impact physical threat.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Purchase business interruption insurance

    Why it's wrong here

    Insurance transfers the financial consequence of a flood but leaves the data centre physically exposed, so the underlying availability risk persists. It is tempting because business interruption cover is the standard treatment for residual loss, and would be correct once relocation or redundancy has reduced the likelihood of outage.

  • ✗

    Move all operations to a cloud provider

    Why it's wrong here

    Moving all operations to a cloud provider changes hosting location but does not guarantee the provider's own facilities avoid flood zones, and it exceeds the scope of treating one site's exposure. It is tempting as a resilience strategy, and would be correct where the requirement is full outsourcing of infrastructure.

  • ✓

    Implement flood barriers and redundant cooling systems

    Why this is correct

    Flood barriers directly mitigate the flood threat at the data centre, while redundant cooling systems address the consequential overheating risk. Together they reduce likelihood and impact without relocating operations, satisfying the risk treatment requirement within the existing facility constraint.

  • ✗

    Accept the risk and document it in the risk register

    Why it's wrong here

    Acceptance leaves the data centre in the floodplain, so the identified risk remains untreated and no control reduces its likelihood or impact. It is tempting because documented acceptance is legitimate for low-rated risks within tolerance, and would be correct if relocation cost outweighed the assessed exposure.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CRISC

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A risk assessment for a healthcare organization reveals a high likelihood of data breaches due to weak encryption on portable devices. The organization decides to deploy full-disk encryption and enforce multi-factor authentication. Which risk response strategy is being applied?

hard
  • A.Transfer
  • B.Acceptance
  • C.Avoidance
  • ✓ D.Mitigation

Why D: Deploying full-disk encryption and multi-factor authentication directly reduces the likelihood and/or impact of data breaches from weak encryption on portable devices. This is the definition of risk mitigation — applying controls to lower risk to an acceptable level. The organization is actively reducing the vulnerability, not transferring, accepting, or avoiding the risk.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.