CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 19


Management receives information indicating a high level of risk associated with potential flooding near the organization's data center with in the next few years. As a result, a decision has been made to move data center operations to another facility on higher ground. Which approach has been adopted?

Show Answer
Correct Answer: D

The approach described in the question involves moving the data center operations to another facility on higher ground to eliminate the risk associated with potential flooding. This action is best characterized as risk avoidance because it involves taking proactive measures to completely avoid the potential risk of flooding by relocating to a safer location.

Discussion

18 comments
Sign in to comment
Victor83516Option: D
Sep 6, 2022

Do not fully agree with the original answer, risk avoidance usually means that the operational target has been cancelled, which means that the data center has ceased to operate. In the context of exam questions, it also seems to be a risk mitigation approach. Risk avoidance in this scenario is only for the risk of flooding, which is not a too standard case.

ObaidManOption: D
Jun 13, 2023

The approach that has been adopted in this scenario is D. Risk avoidance. Risk avoidance involves taking actions to eliminate or avoid the risk altogether. In this case, the decision to move data center operations to another facility on higher ground is a proactive measure to avoid the potential risk of flooding near the current data center location. By relocating the data center to a safer location, the organization is actively avoiding the risk associated with potential flooding.

oldmagicOption: D
Jun 7, 2023

Wow! D is indeed correct. RISK reduction would be if you put sandbags around your DC! A. Risk reduction: This involves taking actions to decrease the potential impact or likelihood of a risk. While moving the data center might reduce the risk of flood damage, it's more accurate to say it completely avoids this particular risk.

crowsaintOption: D
Sep 14, 2023

The answer is D. To avoid risk, data centers must be closed or moved to a cloud environment where there is no risk of flooding. A is the appropriate choice to reduce the risk of flooding.

Forever25Option: A
Oct 14, 2022

I also think that the right answer should A, pretty much moving the data center it can be considered avoiding risk if the data center is not build yet, if its already build and we are moving it to a different location in response to a risk then it is ... risk mitigation/reduction

i91290Option: A
Jun 19, 2023

A is the right answer.

DeeplaxmiOption: A
Sep 25, 2022

I think A.. one cannnot rule out the poosibility that the new facility can also get struck with floods. Hnce risk reduction can be more appropriate answer.

Mike750Option: A
Feb 20, 2023

I would go for A. The risk is reduced but not eliminated (hence avoided).

frisbgOption: A
May 23, 2023

Risk avoidance would be if you close down data center. because risk avoidance mean "Avoiding risk by not allowing actions that would cause the risk to occur". In this case safe and higher ground is chosen therefor appropriate controls are applied to reduce the risk therefor Risk mitigation, answer is A

EBTURKOption: A
May 28, 2023

They don't avoid risk, they take correcting actions

LilikOption: D
Oct 14, 2022

D is the correct answear because according to CRM risk avoidance means avoiding risk by not allowing actions that would cause the risk to occur. Risk acceptance means not taking actions, provided the risk clearly satisfies the organisation s policy and criteria for acceptance. Risk transfer means transfering the risk to other parties such as insurets or suppliers.

joehongOption: A
Jan 7, 2024

A. Risk avoidance means no chance of happening - which means closing data center. Any way that still have a chance are risk reduction

SwallowsOption: D
Apr 6, 2024

The approach described in the question is called risk avoidance.

5b56aaeOption: D
Apr 14, 2024

avoidance

a84nOption: A
Apr 25, 2024

Answer: A

KAP2HURUFOption: D
May 31, 2024

Risk reduction would involve taking steps to lessen the impact or likelihood of the risk occurring but not completely avoiding it. An example of risk reduction in this context might be to enhance flood defenses at the current data center rather than moving it. However, since the organization is moving the data center to eliminate the risk of flooding, the approach is risk avoidance.

Michael Romagnoli
Dec 30, 2024

A is correct just because you move to an area less prone to flooding doesn't mean that flooding can't occur. Things like watermains do fail for example. it's a risk reduction

Kritika Sharma
Apr 30, 2025

A is the correct ans for sure