IsacaIsaca
CRISC · Question #438
CRISC Question #438: Real Exam Question with Answer & Explanation
Sign in or unlock CRISC to reveal the answer and full explanation for question #438. The question stem and answer options stay visible for context.
Submitted by ahmad_uae· Apr 18, 2026Risk Response and Reporting
Question
An organization operates in an environment where the impact of ransomware attacks is high, with a low likelihood. After quantifying the impact of the risk associated with ransomware attacks exceeds the organization's risk appetite and tolerance, which of the following is the risk practitioner's BEST recommendation?
Options
- AObtain adequate cybersecurity insurance coverage.
- BEnsure business continuity assessments are up to date.
- CAdjust the organization's risk appetite and tolerance.
- DObtain certification to a global information security standard.
Unlock CRISC to see the answer
You've previewed enough free CRISC questions. Unlock CRISC for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Risk Response#Business Continuity#Impact Mitigation#Risk Appetite