nerdexam
IsacaIsaca

CRISC · Question #438

CRISC Question #438: Real Exam Question with Answer & Explanation

Sign in or unlock CRISC to reveal the answer and full explanation for question #438. The question stem and answer options stay visible for context.

Submitted by ahmad_uae· Apr 18, 2026Risk Response and Reporting

Question

An organization operates in an environment where the impact of ransomware attacks is high, with a low likelihood. After quantifying the impact of the risk associated with ransomware attacks exceeds the organization's risk appetite and tolerance, which of the following is the risk practitioner's BEST recommendation?

Options

  • AObtain adequate cybersecurity insurance coverage.
  • BEnsure business continuity assessments are up to date.
  • CAdjust the organization's risk appetite and tolerance.
  • DObtain certification to a global information security standard.

Unlock CRISC to see the answer

You've previewed enough free CRISC questions. Unlock CRISC for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Risk Response#Business Continuity#Impact Mitigation#Risk Appetite
Full CRISC PracticeBrowse All CRISC Questions