CRISC Risk Response and Mitigation Strategies 1 — Questions and Answers
Question 1: Which risk response option involves purchasing cyber liability insurance to cover potential losses?
- Risk transfer (Correct answer)
- Risk avoidance
- Risk acceptance
- Risk mitigation
Correct answer: Risk transfer
Risk transfer shifts the financial consequences of a risk to a third party (e.g., an insurer), though it does not eliminate the underlying risk.
Question 2: A company decides to discontinue an e-commerce feature because its security risks are too high. This is an example of:
- Risk avoidance (Correct answer)
- Risk transfer
- Risk acceptance
- Risk mitigation
Correct answer: Risk avoidance
Risk avoidance eliminates the risk entirely by choosing not to engage in the activity that creates the risk.
Question 3: Which factor is MOST important when selecting between risk mitigation options?
- Cost-effectiveness relative to the risk reduction achieved (Correct answer)
- Availability of vendor-supplied solutions
- The IT department's preference for specific technologies
- The speed at which the control can be implemented
Correct answer: Cost-effectiveness relative to the risk reduction achieved
Risk response selection should be driven by whether the cost of the control is justified by the reduction in risk exposure it delivers.
Question 4: Residual risk that remains after mitigation controls are applied should be compared against which benchmark?
- The organization's defined risk tolerance (Correct answer)
- The industry average residual risk level
- The cost of additional controls
- The initial inherent risk score
Correct answer: The organization's defined risk tolerance
Residual risk must be compared to the organization's risk tolerance to determine whether it has been reduced to an acceptable level.
Question 5: Which risk response is MOST appropriate for a low-likelihood, low-impact risk?
- Risk acceptance (Correct answer)
- Risk avoidance
- Risk transfer
- Risk mitigation
Correct answer: Risk acceptance
Low-likelihood, low-impact risks are typically accepted because the cost of mitigation outweighs the potential benefit.
Question 6: A compensating control is BEST described as:
- An alternative control used when a primary control cannot be implemented (Correct answer)
- A control that provides additional layers on top of existing controls
- A detective control that identifies when a risk has materialized
- A control automatically triggered by a monitoring system
Correct answer: An alternative control used when a primary control cannot be implemented
A compensating control substitutes for a primary control when the primary control is impractical or not feasible to implement in a given context.
Which risk response option involves purchasing cyber liability insurance to cover potential losses?