CRISC Risk Response and Mitigation Strategies 2 — Questions and Answers
Question 1: Which element MUST be included in a risk response plan to ensure accountability?
- Named owner responsible for implementing the response (Correct answer)
- A list of all organizational IT assets
- The risk assessment methodology used
- A history of past security incidents
Correct answer: Named owner responsible for implementing the response
A risk response plan must identify a specific owner who is responsible and accountable for executing the response within the agreed timeframe.
Question 2: Which statement BEST describes the difference between a preventive and a detective control?
- Preventive controls stop incidents before they occur; detective controls identify incidents after they begin (Correct answer)
- Preventive controls are manual; detective controls are automated
- Preventive controls reduce impact; detective controls reduce likelihood
- Preventive controls are more expensive than detective controls
Correct answer: Preventive controls stop incidents before they occur; detective controls identify incidents after they begin
Preventive controls block threats before they cause harm, while detective controls identify when a threat event is occurring or has occurred.
Question 3: When a risk cannot be fully mitigated, the BEST course of action is to:
- Formally accept the residual risk with senior management approval (Correct answer)
- Escalate immediately to external regulators
- Implement additional controls regardless of cost
- Document the risk and take no further action
Correct answer: Formally accept the residual risk with senior management approval
Formal acceptance of residual risk by senior management ensures that the decision is deliberate, documented, and appropriately authorized.
Question 4: A corrective control is MOST effective for:
- Minimizing damage and restoring normal operations after a risk event (Correct answer)
- Preventing unauthorized access before it occurs
- Detecting policy violations in real time
- Transferring risk liability to a third party
Correct answer: Minimizing damage and restoring normal operations after a risk event
Corrective controls reduce the impact of a risk that has already materialized by enabling recovery and restoration of normal business operations.
Question 5: Which approach to risk mitigation involves redesigning a business process to eliminate a risk entirely?
- Risk avoidance through process redesign (Correct answer)
- Risk transfer through outsourcing
- Risk acceptance with monitoring
- Risk sharing with business partners
Correct answer: Risk avoidance through process redesign
Redesigning a process to remove the conditions that create the risk is a form of risk avoidance that eliminates the root cause.
Question 6: The PRIMARY purpose of a risk treatment plan is to:
- Document agreed responses to specific risks with timelines and owners (Correct answer)
- Provide technical specifications for security tool deployment
- List all risks identified in the annual risk assessment
- Define the organization's risk appetite and tolerance levels
Correct answer: Document agreed responses to specific risks with timelines and owners
A risk treatment plan captures the specific actions, owners, timelines, and resources needed to implement chosen risk responses.
Which element MUST be included in a risk response plan to ensure accountability?