Certified in Risk and Information Systems Control (CRISC) — Question 279
The PRIMARY objective for selecting risk response options is to:
Answer options
- A. minimize residual risk.
- B. reduce risk factors.
- C. reduce risk to an acceptable level.
- D. identify compensating controls.
Correct answer: C
Explanation
The correct answer is C because the primary aim of risk response options is to lower the risk to a level that is deemed acceptable for the organization. Options A and B focus on minimizing or reducing risks without specifically addressing acceptability, while D addresses a different aspect of risk management that involves identifying controls rather than responding to risk.