Courseiva
IT Risk Assessment →easyMultiple Choice

CRISC IT Risk Assessment Practice Question

Which risk treatment option is being used when an organization decides to stop a business activity that creates a high-risk exposure?

⚠ Common exam trap

Watch out — candidates often confuse 'avoid' with 'mitigate,' thinking that any action to reduce risk is avoidance, but CRISC specifically tests that avoidance means completely eliminating the risk by discontinuing the activity, not just applying controls to lower it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Avoid

When an organization stops a business activity that creates high-risk exposure, it is applying the risk avoidance treatment option. This is a deliberate decision to eliminate the risk entirely by discontinuing the associated process, system, or operation, rather than attempting to reduce or transfer the residual risk. In IT risk management, avoidance is often chosen when the cost or impact of mitigation exceeds the benefit of the activity, or when the risk level is intolerable under any control scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Avoid

    Why this is correct

    Risk avoidance eliminates the exposure entirely by discontinuing the activity that generates it, rather than transferring, mitigating or accepting the risk. Stopping the business activity removes both the likelihood and impact, which is the defining characteristic of the avoid treatment option.

  • ✗

    Accept

    Why it's wrong here

    Accepting retains the activity and its exposure, tolerating the loss if it occurs; the stem describes terminating the activity, which is avoidance. Acceptance is tempting when the cost of treating a risk exceeds the potential impact, making it the right choice for low-probability, low-impact residual risks.

  • ✗

    Mitigate

    Why it's wrong here

    Incorrect; mitigation implements controls to reduce risk.

  • ✗

    Transfer

    Why it's wrong here

    Transfer shifts the financial impact of a risk to a third party, such as an insurer, while the activity continues. Terminating the activity removes the exposure entirely, which is risk avoidance. Transfer would be the correct treatment when the organisation retains the activity but wants another party to absorb the loss.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.