hardMultiple Choice
CRISC Practice Question: Your organization is undergoing a merger and…
Your organization is undergoing a merger and acquisition. The IT risk assessment team is tasked with evaluating the target company's IT environment. During the assessment, you discover that the target company uses a legacy ERP system that is no longer supported by the vendor. They have no disaster recovery plan for this system, and it contains financial data critical to the merged entity. The integration timeline is aggressive, and replacing the system would delay the merger by 18 months. The executive team is reluctant to delay. What is the BEST risk treatment option?
⚠ Common exam trap
Many candidates choose Option B (accept the risk) because the system has been stable historically, but CRISC expects you to recognize that unsupported systems with no DR plan represent an unmanaged risk that requires active mitigation, not passive acceptance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mitigate by developing a disaster recovery plan and implementing compensating controls such as regular backups and manual procedures.
The legacy ERP system contains critical financial data and cannot be replaced without an 18-month delay, making risk mitigation the most practical approach. Developing a disaster recovery plan and implementing compensating controls (e.g., regular backups, manual procedures) reduces the likelihood and impact of a system failure while allowing the merger to proceed on schedule. This aligns with the CRISC principle of treating risk by reducing residual risk to an acceptable level without blocking business objectives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Avoid the risk by excluding the legacy system from the merger and migrating data to a new system.
Why it's wrong here
Excluding the system does not remove the risk: the financial data must still be migrated and the legacy platform retired, which is the 18-month replacement the executives rejected. It is tempting because avoidance sounds decisive, and would be correct if the capability could simply be discontinued without retaining the data.
- ✗
Accept the risk because the system has been running for years without issue.
Why it's wrong here
Acceptance leaves critical financial data on an unsupported platform with no recovery capability, exceeding the organization's risk appetite without executive sign-off. It is tempting because the system has operated without incident, and acceptance would be correct for a low-impact system with documented tolerance and contingency funding.
- ✓
Mitigate by developing a disaster recovery plan and implementing compensating controls such as regular backups and manual procedures.
Why this is correct
Replacing the unsupported ERP would delay the merger 18 months, which executives reject, so mitigation is the viable treatment. A disaster recovery plan plus backups and manual procedures addresses the absence of recovery capability while compensating for the vendor's withdrawn support.
- ✗
Transfer the risk to the target company's previous owners.
Why it's wrong here
Previous owners cannot assume risk for a system the merged entity will own and operate; risk transfer requires a counterparty contract such as cyber insurance or vendor indemnity. It is tempting because transfer is a recognised treatment, and would be correct where a willing third party contractually accepts the financial loss.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.