Courseiva
mediumMultiple Choice

CRISC Practice Question: A risk analyst for a financial institution that…

You are a risk analyst for a financial institution that uses a legacy mainframe system for core banking transactions. The mainframe is critical for daily operations, but it is no longer supported by the vendor. The system has known vulnerabilities that cannot be patched due to compatibility issues. The institution has a risk appetite that is very low for any disruption to core banking services. Recently, there was a minor outage caused by a hardware failure, which was resolved quickly, but it highlighted the system's fragility. The IT director proposes to migrate to a modern system, but the migration will take 2 years and cost $5 million. The board is concerned about the cost and timeline. You need to recommend an immediate risk treatment to reduce the likelihood of a major outage while the migration is underway. Which of the following is the BEST course of action?

⚠ Common exam trap

Many candidates choose option D (insurance) because it seems like a quick financial fix, but CRISC emphasizes that risk treatment must first address likelihood reduction before considering financial transfer, especially when the risk appetite is very low.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement redundant hardware for critical components and conduct regular failover testing.

Implementing redundant hardware for critical components and conducting regular failover testing directly reduces the likelihood of a major outage by addressing the single point of failure exposed by the recent hardware failure. This is an immediate risk treatment that does not depend on the 2-year migration timeline, and it aligns with the institution's very low risk appetite for core banking disruption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Accept the risk because the migration plan is in place.

    Why it's wrong here

    Acceptance leaves the known unpatched vulnerabilities and fragile hardware unaddressed, contradicting the institution's very low appetite for core banking disruption. It is tempting because a two-year migration is already funded, but that project does not reduce the likelihood of an outage occurring during the interim period.

  • ✓

    Implement redundant hardware for critical components and conduct regular failover testing.

    Why this is correct

    Redundant hardware plus failover testing reduces the likelihood that a single component failure causes a major outage, addressing the fragility highlighted by the recent incident. It is immediate, unlike the two-year migration, and suits the very low disruption appetite.

  • ✗

    Negotiate with the vendor for extended support.

    Why it's wrong here

    The vendor no longer supports the mainframe, so extended support cannot be negotiated; the stem states support has ended and vulnerabilities cannot be patched. It is tempting because vendor support is a standard compensating control, but that route is unavailable here, leaving resilience measures as the viable immediate treatment.

  • ✗

    Purchase business interruption insurance to cover potential losses.

    Why it's wrong here

    Insurance transfers financial loss after an outage; it does not reduce the likelihood of a major outage, which is the stated objective. It is tempting because it addresses the low risk appetite financially, but the question asks for likelihood reduction while migration proceeds, which only resilience or redundancy controls deliver.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.