An organization plans to provide specific cloud security training for the IT team to help manage risks associated with cloud technology. This response is considered risk:
Correct Answer: B
Risk mitigation involves implementing measures to reduce either the likelihood or impact of a risk.
By providing targeted training, the organization increases staff capability, thereby reducing the likelihood of misconfigurations or compliance errors in cloud usage.
ISACA defines mitigation as:
"Implementing controls or training to reduce exposure to risk within acceptable levels."
* A Transfer = insurance or outsourcing.
* C Acceptance = no action.
* D Deferral = postponing response.
Hence, B. Mitigation is correct.
CRISC Reference: Domain 3 - Risk Response and Mitigation, Topic: Risk Response Options.