Exam CISA All QuestionsBrowse all questions from this exam
Question 19

Management receives information indicating a high level of risk associated with potential flooding near the organization's data center with in the next few years. As a result, a decision has been made to move data center operations to another facility on higher ground. Which approach has been adopted?

    Correct Answer: D

    The approach described in the question involves moving the data center operations to another facility on higher ground to eliminate the risk associated with potential flooding. This action is best characterized as risk avoidance because it involves taking proactive measures to completely avoid the potential risk of flooding by relocating to a safer location.

Discussion
Victor83516Option: D

Do not fully agree with the original answer, risk avoidance usually means that the operational target has been cancelled, which means that the data center has ceased to operate. In the context of exam questions, it also seems to be a risk mitigation approach. Risk avoidance in this scenario is only for the risk of flooding, which is not a too standard case.

ObaidManOption: D

The approach that has been adopted in this scenario is D. Risk avoidance. Risk avoidance involves taking actions to eliminate or avoid the risk altogether. In this case, the decision to move data center operations to another facility on higher ground is a proactive measure to avoid the potential risk of flooding near the current data center location. By relocating the data center to a safer location, the organization is actively avoiding the risk associated with potential flooding.

oldmagicOption: D

Wow! D is indeed correct. RISK reduction would be if you put sandbags around your DC! A. Risk reduction: This involves taking actions to decrease the potential impact or likelihood of a risk. While moving the data center might reduce the risk of flood damage, it's more accurate to say it completely avoids this particular risk.

crowsaintOption: D

The answer is D. To avoid risk, data centers must be closed or moved to a cloud environment where there is no risk of flooding. A is the appropriate choice to reduce the risk of flooding.

i91290Option: A

A is the right answer.

Forever25Option: A

I also think that the right answer should A, pretty much moving the data center it can be considered avoiding risk if the data center is not build yet, if its already build and we are moving it to a different location in response to a risk then it is ... risk mitigation/reduction

EBTURKOption: A

They don't avoid risk, they take correcting actions

frisbgOption: A

Risk avoidance would be if you close down data center. because risk avoidance mean "Avoiding risk by not allowing actions that would cause the risk to occur". In this case safe and higher ground is chosen therefor appropriate controls are applied to reduce the risk therefor Risk mitigation, answer is A

Mike750Option: A

I would go for A. The risk is reduced but not eliminated (hence avoided).

DeeplaxmiOption: A

I think A.. one cannnot rule out the poosibility that the new facility can also get struck with floods. Hnce risk reduction can be more appropriate answer.

KAP2HURUFOption: D

Risk reduction would involve taking steps to lessen the impact or likelihood of the risk occurring but not completely avoiding it. An example of risk reduction in this context might be to enhance flood defenses at the current data center rather than moving it. However, since the organization is moving the data center to eliminate the risk of flooding, the approach is risk avoidance.

a84nOption: A

Answer: A

5b56aaeOption: D

avoidance

SwallowsOption: D

The approach described in the question is called risk avoidance.

joehongOption: A

A. Risk avoidance means no chance of happening - which means closing data center. Any way that still have a chance are risk reduction

LilikOption: D

D is the correct answear because according to CRM risk avoidance means avoiding risk by not allowing actions that would cause the risk to occur. Risk acceptance means not taking actions, provided the risk clearly satisfies the organisation s policy and criteria for acceptance. Risk transfer means transfering the risk to other parties such as insurets or suppliers.