nerdexam
Isaca

CRISC · Question #582

Because of a potential data breach, an organization has decided to temporarily shut down its online sales order system until sufficient controls can be implemented. Which risk treatment has been…

The correct answer is A. Avoidance. By temporarily shutting down an online sales system due to a potential data breach, the organization is employing risk avoidance by eliminating the activity that causes the risk.

Submitted by femi9· Apr 18, 2026Risk Response and Reporting

Question

Because of a potential data breach, an organization has decided to temporarily shut down its online sales order system until sufficient controls can be implemented. Which risk treatment has been selected?

Options

  • AAvoidance
  • BAcceptance
  • CMitigation
  • DTransfer

How the community answered

(48 responses)
  • A
    90% (43)
  • B
    2% (1)
  • C
    6% (3)
  • D
    2% (1)

Why each option

By temporarily shutting down an online sales system due to a potential data breach, the organization is employing risk avoidance by eliminating the activity that causes the risk.

AAvoidanceCorrect

Risk avoidance involves making a conscious decision to not engage in an activity or to stop an activity that carries a high level of risk. By temporarily shutting down the online sales order system, the organization completely eliminates the exposure to the potential data breach risk, thus avoiding it.

BAcceptance

Risk acceptance is when an organization acknowledges a risk and decides to take no action to reduce it, which is contrary to shutting down the system.

CMitigation

Risk mitigation involves taking steps to reduce the likelihood or impact of a risk, such as implementing new controls, but shutting down the system eliminates the risk, rather than just reducing it.

DTransfer

Risk transfer involves shifting the financial burden or responsibility of a risk to a third party, often through insurance or contracts, which is not what shutting down a system achieves.

Concept tested: Risk treatment strategies (avoidance)

Source: https://learn.microsoft.com/en-us/compliance/regulatory/risk-assessment-template-introduction

Topics

#Risk avoidance#Risk treatment strategies#Information security risk#Data breach

Community Discussion

No community discussion yet for this question.

Full CRISC Practice