Certified Information Systems Auditor (CISA) — Question 1110

Management has agreed to move the organization's data center due to recent flood map changes in its current location. Which risk response has been adopted?

Answer options

Correct answer: B

Explanation

The correct answer is B, Risk avoidance, as relocating the data center eliminates the risk of flooding at the current location. Risk elimination would mean completely removing the risk, which is not applicable here, while risk acceptance implies acknowledging the risk without taking action, and risk transfer involves shifting the risk to another party, neither of which applies to moving the data center.