Courseiva

CRISC · topic practice

Risk Response and Mitigation practice questions

This domain covers selecting, implementing, and validating risk responses—mitigation, transfer, avoidance, and acceptance—and tracking residual risk against appetite. Questions test sequencing control implementation, classifying response types, and judging whether proceeding above appetite with monitoring is acceptable. Expect scenario-based items tied to risk register updates and control ownership.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Risk Response and Mitigation

What the exam tests

What to know about Risk Response and Mitigation

Be able to pick the correct risk response for a scenario, order treatment steps, and classify controls. The key is recognizing that residual risk above appetite requires explicit acceptance by the accountable owner, not silent continuation.

Classifying responses as mitigate, transfer, avoid, or accept for a given scenario

Sequencing risk treatment steps: assess, select response, implement controls, monitor residual risk

Distinguishing preventive, detective, and corrective controls and their placement in the process

Determining whether residual risk above appetite can proceed with monitoring and approval

Watch out for

Common Risk Response and Mitigation exam traps

  • ▸Treating risk acceptance as a failure of response rather than a valid, documented decision with owner sign-off
  • ▸Confusing risk transfer (insurance, contracts) with risk mitigation, which reduces likelihood or impact directly
  • ▸Skipping control effectiveness testing and assuming implementation equals reduced residual risk

Practice set

Risk Response and Mitigation questions

20 questions · select your answer, then reveal the explanation

Which TWO of the following are effective risk mitigation strategies for reducing the likelihood of a ransomware attack?

Question 2easymultiple choice
Study the full ACL explanation →

Refer to the exhibit. A risk practitioner is reviewing the access control list for a critical server. The ACL is applied inbound on the interface connecting to the internet. Which of the following is the MOST significant risk?

Exhibit

Refer to the exhibit.

Access List: ACL-01
10 deny ip host 10.1.1.10 any
20 permit tcp 10.1.1.0 0.0.0.255 any eq 443
30 permit udp 10.1.1.0 0.0.0.255 any eq 53
40 deny ip any any

A risk assessment for a financial trading platform has identified a high-risk vulnerability in the order matching engine. The risk owner has recommended implementing compensating controls rather than fixing the underlying code. Which TWO of the following are valid compensating controls? (Choose two.)

Match each risk management process step to its activity.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Find and list potential risks

Determine likelihood and impact

Compare risk levels to risk criteria

Select and implement controls

An organization is considering outsourcing its IT support to a third-party provider. The risk manager has identified that the provider's data handling practices may not comply with regulatory requirements. Which of the following is the BEST risk response strategy?

A multinational corporation is evaluating a new vendor for cloud services. The vendor's data centers are located in a country with weak data protection laws. The corporation's data includes personal information of EU citizens subject to GDPR. What is the MOST appropriate risk response?

Which TWO of the following are valid reasons to accept a risk rather than mitigate it?

Refer to the exhibit. Which of the following is the MOST critical risk that should be addressed first?

Exhibit

Refer to the exhibit.

Exhibit: Results from a vulnerability scan

```
Vulnerability Scan Report - 2024-01-15
Target: 192.168.1.0/24

Host: 192.168.1.10
  Port 22/tcp: SSH protocol version 1.0 (critical)
  Port 80/tcp: Apache HTTP Server 2.2.3 (high)
  Port 443/tcp: OpenSSL 0.9.8 (high)

Host: 192.168.1.20
  Port 3389/tcp: RDP with weak encryption (medium)
  Port 445/tcp: SMB signing not required (medium)
```

Refer to the exhibit. An organization uses this firewall access list. What is the MOST significant risk associated with this configuration?

Exhibit

Refer to the exhibit.

Exhibit: Firewall rule configuration

```
access-list 100 permit tcp any any eq 80
access-list 100 permit tcp any any eq 443
access-list 100 permit tcp 10.0.0.0 0.255.255.255 any eq 22
access-list 100 deny ip any any
```

Refer to the exhibit. Which type of attack is MOST likely indicated by these log entries?

Exhibit

Refer to the exhibit.

Exhibit: Error log from a web application

```
2024-07-22 14:23:45 ERROR: org.hibernate.exception.ConstraintViolationException: could not execute statement
2024-07-22 14:23:45 ERROR: java.sql.SQLException: Duplicate entry 'admin' for key 'username'
2024-07-22 14:23:46 INFO: User 'admin' login successful
```

During a post-mortem of a security incident, the risk manager notes that the response team failed to execute the incident response plan correctly because the plan was outdated. Which of the following is the BEST corrective action?

Based on the exhibit, which risk response should be prioritized?

Exhibit

Refer to the exhibit.

SIEM alert log:
Time: 2025-03-20 14:23:45
Source IP: 10.0.1.50
Destination: server1.company.local (192.168.1.10)
Event: Multiple failed logins (15 attempts in 30 seconds)
Current state: No account lockout policy enabled.

An organization assesses a risk of intellectual property theft through email exfiltration. They decide to enforce DLP controls, purchase a cyber liability policy, and officially accept the residual risk after controls. Which THREE risk response options are demonstrated?

Refer to the exhibit. Based on the risk register, which risk response is applied to the risk with the highest inherent risk?

Exhibit

Risk ID | Inherent Risk | Controls | Residual Risk | Response
Risk-001 | High | Firewall, IDS | Medium | Transfer
Risk-002 | Medium | Encryption | Low | Accept
Risk-003 | Critical | None | Critical | Mitigate

Refer to the exhibit. A risk manager reviews the vulnerability scan output. According to the policy, what is the required risk response?

Exhibit

Vulnerability ID: VULN-001
Severity: Critical
CVSS: 9.8
Port: 443
Service: HTTPS
Status: Open

Policy: All vulnerabilities with CVSS >= 9.0 must be remediated within 7 days.

GlobalTech Inc., a multinational corporation, is planning to migrate its customer data to a new cloud platform. The migration involves transferring sensitive personally identifiable information (PII) from an on-premises database to a cloud-based CRM. The risk manager conducted a risk assessment and identified several risks, including unauthorized access during transit and residual data exposure due to misconfiguration. Mitigation controls include encryption in transit, encryption at rest, and strict access controls. The residual risk after mitigation is assessed as medium. The risk appetite statement defines that 'No data breach incidents resulting in regulatory fines exceeding $1 million are acceptable.' The estimated potential fine from a breach is $5 million with a likelihood of 2% after controls. The cost of additional controls to reduce likelihood to 0.5% is $500,000. The migrating team proposes to purchase cyber insurance with a $3 million coverage for $200,000 annual premium. The board of directors prefers to accept the residual risk to avoid additional costs. What should the risk manager do?

Refer to the exhibit. Given the organization's risk appetite is Low, which risk response is most appropriate?

Exhibit

Refer to the exhibit.
Risk Register Excerpt:
Asset: Customer Database
Inherent Risk (Likelihood: High, Impact: High) => High
Control Set: Access controls (effective), Encryption (effective), Intrusion Detection (moderate)
Current Residual Risk: Medium
Mitigation Options:
A. Implement additional monitoring (cost: $50k, reduces residual to Low)
B. Accept the residual risk (cost: $0)
C. Transfer via cyber insurance (premium: $30k)
D. Avoid by discontinuing database operations (cost: $2M)
What is the most appropriate risk response given the current residual risk is Medium and the organization's risk appetite is Low?

A multinational corporation has recently experienced a significant increase in phishing attacks targeting its employees. The attacks have caused several data breaches, resulting in regulatory fines and reputational damage. The organization has implemented security awareness training for all employees, but the number of successful attacks remains high. Additionally, the organization's risk appetite for cybersecurity incidents is Low. The CRO has asked you to recommend a risk response. You have the following options:

A. Accept the risk because the training has reduced the likelihood, and further controls are too expensive. B. Transfer the risk by outsourcing all email and security operations to a managed security service provider (MSSP). C. Implement technical controls such as advanced email filtering and multi-factor authentication (MFA) to reduce the likelihood and impact of phishing attacks. D. Avoid the risk by discontinuing the use of email for business communications.

Which course of action is most appropriate given the organization's risk appetite and the current situation?

A risk practitioner is reviewing the organization's risk response plan for a critical business process. The plan includes several controls to address identified risks. Which of the following are examples of risk mitigation controls? (Choose two.)

A healthcare organization is implementing a new electronic health record (EHR) system. The risk committee has approved a risk treatment plan that includes a requirement for multi-factor authentication (MFA) for all clinical staff. During implementation, the vendor states that MFA is not supported for the emergency department's rapid login workflow. The project manager asks the risk practitioner to recommend the MOST appropriate action.

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Risk Response and Mitigation sessions

Start a Risk Response and Mitigation only practice session

Every question in these sessions is drawn from the Risk Response and Mitigation domain — nothing else.

Related practice questions

Related CRISC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CRISC exam test about Risk Response and Mitigation?
Be able to pick the correct risk response for a scenario, order treatment steps, and classify controls. The key is recognizing that residual risk above appetite requires explicit acceptance by the accountable owner, not silent continuation.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Risk Response and Mitigation questions in a focused session?
Yes — the session launcher on this page draws every question from the Risk Response and Mitigation domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CRISC topics?
Use the topic links above to move to related areas, or go back to the CRISC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CRISC exam covers. They are not copied from any real exam or dump site.