mediumMultiple Choice
CRISC Practice Question: The IT risk manager at a multinational…
You are the IT risk manager at a multinational corporation that recently migrated its customer database to a cloud-based platform. The database contains personally identifiable information (PII) subject to GDPR. During a routine vulnerability scan, you discover that the database is accessible from the internet without encryption (port 1433 open). The cloud provider's shared responsibility model indicates that securing the database configuration is the customer's responsibility. You have identified the risk as high likelihood and high impact. The business owner argues that the database is only accessible to a limited IP range and that encryption would degrade performance. Which course of action should you recommend to treat the risk?
⚠ Common exam trap
CRISC often tests the confusion between risk transfer and risk mitigation; insurance does not reduce the risk itself, only its financial impact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Close the port or implement a VPN, and enforce encryption
The risk is high likelihood and high impact, and the database is exposed to the internet without encryption, violating GDPR. The most effective risk treatment is to mitigate the risk by closing the port or using a VPN and enforcing encryption. This directly addresses the vulnerability and reduces both likelihood and impact. Other options do not adequately treat the risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transfer the risk by purchasing cyber insurance
Why it's wrong here
Cyber insurance compensates financial loss after a breach but does not remove the unencrypted internet-facing port 1433 or satisfy GDPR's obligation to secure PII. It is tempting because transfer shifts residual financial impact, and would be appropriate as a supplementary control alongside remediation, not as the primary treatment.
- ✓
Close the port or implement a VPN, and enforce encryption
Why this is correct
Closing port 1433 or tunnelling via VPN removes internet exposure, and encryption protects PII in transit, directly addressing the GDPR confidentiality risk. This treats both the high-likelihood access path and the unencrypted transmission, rather than accepting the business owner's performance argument.
- ✗
Accept the risk because the IP restriction reduces likelihood
Why it's wrong here
Accepting leaves an unencrypted, internet-reachable database holding PII, breaching GDPR's requirement for appropriate technical measures regardless of IP filtering. It is tempting because a limited IP range does lower exposure, and acceptance would be defensible for a low-impact, low-likelihood risk rather than the high/high rating recorded.
- ✗
Implement a web application firewall (WAF) to monitor traffic
Why it's wrong here
A WAF filters HTTP/HTTPS application-layer traffic and cannot encrypt a directly exposed SQL Server port 1433 or restrict its network reachability. It is tempting because WAFs protect web-facing applications, and would be right for defending an HTTP endpoint, but here the fix is network isolation plus encryption.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.