Courseiva
mediumMultiple Choice

CRISC Practice Question: The IT risk manager at a multinational…

You are the IT risk manager at a multinational corporation that recently migrated its customer database to a cloud-based platform. The database contains personally identifiable information (PII) subject to GDPR. During a routine vulnerability scan, you discover that the database is accessible from the internet without encryption (port 1433 open). The cloud provider's shared responsibility model indicates that securing the database configuration is the customer's responsibility. You have identified the risk as high likelihood and high impact. The business owner argues that the database is only accessible to a limited IP range and that encryption would degrade performance. Which course of action should you recommend to treat the risk?

⚠ Common exam trap

CRISC often tests the confusion between risk transfer and risk mitigation; insurance does not reduce the risk itself, only its financial impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Close the port or implement a VPN, and enforce encryption

The risk is high likelihood and high impact, and the database is exposed to the internet without encryption, violating GDPR. The most effective risk treatment is to mitigate the risk by closing the port or using a VPN and enforcing encryption. This directly addresses the vulnerability and reduces both likelihood and impact. Other options do not adequately treat the risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Transfer the risk by purchasing cyber insurance

    Why it's wrong here

    Cyber insurance compensates financial loss after a breach but does not remove the unencrypted internet-facing port 1433 or satisfy GDPR's obligation to secure PII. It is tempting because transfer shifts residual financial impact, and would be appropriate as a supplementary control alongside remediation, not as the primary treatment.

  • ✓

    Close the port or implement a VPN, and enforce encryption

    Why this is correct

    Closing port 1433 or tunnelling via VPN removes internet exposure, and encryption protects PII in transit, directly addressing the GDPR confidentiality risk. This treats both the high-likelihood access path and the unencrypted transmission, rather than accepting the business owner's performance argument.

  • ✗

    Accept the risk because the IP restriction reduces likelihood

    Why it's wrong here

    Accepting leaves an unencrypted, internet-reachable database holding PII, breaching GDPR's requirement for appropriate technical measures regardless of IP filtering. It is tempting because a limited IP range does lower exposure, and acceptance would be defensible for a low-impact, low-likelihood risk rather than the high/high rating recorded.

  • ✗

    Implement a web application firewall (WAF) to monitor traffic

    Why it's wrong here

    A WAF filters HTTP/HTTPS application-layer traffic and cannot encrypt a directly exposed SQL Server port 1433 or restrict its network reachability. It is tempting because WAFs protect web-facing applications, and would be right for defending an HTTP endpoint, but here the fix is network isolation plus encryption.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.