easyMultiple ChoiceObjective-mapped
CRISC Practice Question: The IT risk manager for a financial institution…
You are the IT risk manager for a financial institution that processes high-value transactions. The organization uses a cloud-based core banking system and on-premises servers for backup. During a recent risk assessment, you identified that the cloud provider's service-level agreement (SLA) guarantees 99.9% uptime, but the organization's business impact analysis (BIA) indicates that every hour of downtime costs $500,000. The current recovery time objective (RTO) for the core banking system is 4 hours, but the actual recovery capability is 6 hours due to manual steps in failover. The risk owner has accepted this risk informally. You are asked to recommend a course of action to the risk committee. Which of the following is the most appropriate recommendation?
⚠ Common exam trap
Watch out — candidates often confuse the cloud provider's SLA with the organization's RTO/RTA gap, or assume informal risk acceptance is sufficient, when CRISC emphasizes formal documentation and committee-level decision-making for risks exceeding thresholds.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the risk gap (actual recovery of 6 hours vs. RTO of 4 hours) and present it to the risk committee for formal risk acceptance or remediation.
The organization has a critical risk gap: the actual recovery capability (6 hours) exceeds the stated RTO (4 hours), meaning the business would incur $1M in losses (2 hours × $500K) before recovery completes. The risk owner's informal acceptance is insufficient for a financial institution processing high-value transactions; formal documentation and risk committee approval are required for governance and regulatory compliance. Presenting the gap enables informed decision-making on whether to accept the risk formally or invest in remediation (e.g., automating failover to meet the 4-hour RTO).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the risk because the cloud provider's SLA covers 99.9% uptime.
Why it's wrong here
The SLA does not address the recovery capability gap, and the impact of downtime is substantial.
- ✗
Continue with informal acceptance since the risk owner has already accepted it.
Why it's wrong here
Informal acceptance lacks proper documentation and oversight, which is not appropriate for high-impact risks.
- ✗
Reduce the RTO to 2 hours to align with industry best practices.
Why it's wrong here
Reducing the RTO without improving actual recovery capability would widen the gap and increase risk.
- ✓
Document the risk gap (actual recovery of 6 hours vs. RTO of 4 hours) and present it to the risk committee for formal risk acceptance or remediation.
Why this is correct
Formal documentation and escalation ensure the risk is properly managed and decisions are recorded.
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.