Practice questions › Healthcare Information and Systems Management › Privacy and Security
Lowering risk to an acceptable level: mitigation with controls
A practice question in the style of the CPHIMS® exam, from the free questions of HealthITPrep. The question is in English, as in the exam.
A risk assessment finds that unencrypted laptops pose an unacceptable risk. Leadership wants to actually lower that risk to an acceptable level. Which response achieves this?
Choose an answer, or open the explanation below.
Show the answer and the explanation
The correct answer: A. Implement safeguards such as full-disk encryption to mitigate the risk
✅ Why this answer
Three of the four risk responses in one question (mitigate, transfer, accept; the fourth, avoid, is not among the options), and the key is in the question’s verb: “lower that risk to an acceptable level”; which response reduces the risk itself? Mitigate: controls that reduce the likelihood or the impact (such as full-disk encryption), and it is the only option here that changes the risk itself.
❌ Why the other options are wrong
- Cyber insurance to transfer the risk (B): transfers the financial impact to a third party; the incident happens just the same, and only the bill moves. Legitimate, but not “lowering”.
- Documenting and accepting (C): a conscious, documented decision to live with it (for small risks, or those whose remedy costs more than they do); legitimate, but it lowers nothing, and leadership wants it lowered.
- Ignoring it until an incident (D): the only response that is never legitimate. The difference from acceptance: acceptance is a documented decision after assessment, and ignoring is the absence of a decision.
💡 Key concept
The exam rule: the question’s verb picks the response. “Lower the risk” → mitigate. “Transfer the financial impact” → transfer. “A small risk whose remedy costs more than it does” → accept. “Stop the activity itself” → avoid. Ignoring is always wrong.
In the exam: among these options only mitigation lowers the risk itself, because it reduces its likelihood or its impact with controls. (Avoidance removes the risk altogether by stopping the activity, but it is not offered here.) Insurance moves the bill and does not prevent the event. Acceptance is a documented decision after an assessment; ignoring is the absence of a decision.
🔗 Related facts and questions
- The fourth response, avoidance: stopping the activity the risk comes from.
Practice question: management decides that no patient information will be stored on laptops, and that it will stay on the servers only. Which response is this? → Avoidance. - Transfer is not mitigation:
Practice question: an organization bought insurance against cyberattacks and considered the ransomware risk dealt with. What is wrong? → A confusion of transfer with mitigation. Insurance covers the cost and does not prevent the attack. The right way is both together: controls, then an insurance policy. - Residual risk: what remains after the controls are applied. It is compared with the risk the organization is willing to carry (its risk appetite): if it is below that, it is accepted; if not, controls are added.
Practice question: after the laptops are encrypted, there remains the chance that users choose weak passwords. What is this risk called? → Residual risk. - Kinds of controls by function: preventive controls stop the event, such as encryption and access control. Detective controls discover it, such as reviewing audit logs. Corrective controls deal with its effect, such as restoring from a backup.
Practice question: a review of the audit log showed an unauthorized access that happened yesterday. Which kind of control is this review? → Detective. - The risk register: a document that lists each risk, its likelihood and impact, its owner, the response chosen for it and its status. It is reviewed regularly, because likelihood and impact change.
Practice question: management decided to accept a small risk after assessing it. Where is that decision documented, with the name of the risk owner and the date of the next review? → In the risk register. This record is what separates acceptance from ignoring. - Treating a risk in other questions: compensating controls (a related question in the full bank) and redundancy (a related question in the full bank) are faces of mitigation. A contingency plan (a related question in the full bank) is prepared in advance and activated only if the event happens.
40 questions like this one, free
A timed 20-question trial exam with this kind of explanation for every option and a score per domain, drawn from 40 free questions. No payment details needed.
Start the trial examAll 30 free practice questions · CPHIMS guide
Practice questions written for study; they are not the questions of the real exam. An independent site, not affiliated with or endorsed by HIMSS. CPHIMS® is a registered trademark of HIMSS.