nerdexam
Isaca

CRISC · Question #421

An organization has established a contract with a vendor that includes penalties for loss of availability. Which risk treatment has been adopted by the organization?

The correct answer is C. Transfer. The organization's adoption of contractual penalties for loss of availability with a vendor represents a strategy to shift the financial consequences of risk.

Submitted by krish.m· Apr 18, 2026Risk Response and Reporting

Question

An organization has established a contract with a vendor that includes penalties for loss of availability. Which risk treatment has been adopted by the organization?

Options

  • AAcceptance
  • BAvoidance
  • CTransfer
  • DReduction

How the community answered

(53 responses)
  • A
    2% (1)
  • B
    6% (3)
  • C
    91% (48)
  • D
    2% (1)

Why each option

The organization's adoption of contractual penalties for loss of availability with a vendor represents a strategy to shift the financial consequences of risk.

AAcceptance

Acceptance means acknowledging a risk and taking no action to reduce or mitigate its impact or likelihood, which is not the case when contractual penalties are established.

BAvoidance

Avoidance means eliminating the risk by choosing not to engage in the activity that creates it, which is contrary to establishing a contract with a vendor.

CTransferCorrect

Risk transfer involves shifting the financial consequences or operational responsibility of a risk to another party, typically through contractual agreements like penalties for non-performance by a vendor. In this scenario, the organization transfers part of the risk's financial burden to the vendor by embedding penalty clauses in the contract for availability losses.

DReduction

Reduction involves implementing controls to lessen the likelihood or impact of a risk event, whereas contractual penalties deal with the financial consequence after an event occurs.

Concept tested: Risk treatment strategy (transfer)

Source: https://learn.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-governance-strategy-risk-management#gv-1-establish-and-implement-an-enterprise-wide-risk-management-strategy

Topics

#Risk Treatment#Risk Transfer#Vendor Management#Contract Management

Community Discussion

No community discussion yet for this question.

Full CRISC Practice