Courseiva
mediumMultiple Select

CRISC Practice Question: Which TWO of the following are examples of risk…

Which TWO of the following are examples of risk avoidance?

⚠ Common exam trap

It's easy for candidates to confuse risk mitigation (e.g., implementing controls like firewalls) with risk avoidance, failing to recognize that avoidance requires completely eliminating the risk source, not just reducing it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Migrating to a different technology platform

Risk avoidance means eliminating the activity or exposure that creates the risk entirely, rather than mitigating, transferring, or accepting it. Option D (Migrating to a different technology platform) is correct because replacing a vulnerable or risky platform removes the exposure associated with the original technology, thereby avoiding the risk rather than merely reducing it. Option E (Discontinuing a high-risk business process) is correct because ceasing the process altogether eliminates the risk source, which is the defining characteristic of risk avoidance. Option A (Implementing a firewall) is incorrect because a firewall is a risk mitigation control that reduces likelihood or impact while the underlying activity continues. Option B (Purchasing cyber insurance) is incorrect because it transfers financial risk to an insurer, not avoids it. Option C (Accepting the risk) is incorrect because acceptance means retaining the risk with no action to eliminate it, which is the opposite of avoidance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implementing a firewall

    Why it's wrong here

    A firewall mitigates the likelihood of intrusion but leaves the risk present, which is risk mitigation rather than avoidance. It would be the right control where the goal is to reduce, not eliminate, exposure to network attacks.

  • ✗

    Purchasing cyber insurance

    Why it's wrong here

    Insurance transfers the financial consequence to a third party while the risk remains, which is risk transference. It is the correct treatment where the loss is insurable and the organisation prefers to fund rather than eliminate the exposure.

  • ✗

    Accepting the risk

    Why it's wrong here

    Accepting a risk retains it and funds any loss, which is risk acceptance, not avoidance. Acceptance is the correct treatment when the cost of mitigation exceeds the potential loss and the exposure is within tolerance.

  • ✓

    Migrating to a different technology platform

    Why this is correct

    Migrating to a different technology platform eliminates the exposure entirely by removing the vulnerable or high-risk technology from the environment, rather than mitigating, transferring or accepting it. This makes it a genuine example of risk avoidance, as the risk source ceases to exist.

  • ✓

    Discontinuing a high-risk business process

    Why this is correct

    Discontinuing a high-risk business process removes the activity that generates the risk, so the exposure no longer exists. This is the defining characteristic of risk avoidance, distinguishing it from mitigation, transfer or acceptance, where the underlying activity continues in some form.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.