ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During a risk assessment of a payment-processing system, you discover that a single uninterruptible power supply (UPS) is the only source of backup power for the server room. The business impact analysis shows the application cannot tolerate even one hour of downtime. According to standard risk-management practice, which risk response should the organization emphasize for the power-loss threat?
Avoid the risk by shutting down on-premises operations and moving all processing to a third-party cloud provider.
Transfer the risk by purchasing insurance to cover financial loss from downtime.
Accept the risk and document the potential outage in the system security plan.
Mitigate the risk by adding redundant power sources and fail-over capacity.
Because the organization has almost no outage tolerance, it needs to reduce the likelihood and impact of power loss rather than simply accept or shift the risk. Implementing additional UPS units, generators, or dual utility feeds directly treats the vulnerability; this is the definition of risk mitigation. Acceptance leaves the business-critical system exposed, transfer (for example, insurance) only compensates after the fact, and avoidance would require eliminating on-premises processing altogether-rarely practical for a production payment environment.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is risk mitigation in risk management?
Open an interactive chat with Bash
Why is redundancy important for critical systems?
Open an interactive chat with Bash
What is a Business Impact Analysis (BIA) and its role in risk management?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .