mediumMultiple SelectObjective-mapped
CAS-004 Practice Question: A security architect is designing a risk…
A security architect is designing a risk mitigation strategy for a critical application. Which TWO of the following are examples of risk acceptance? (Select TWO.)
⚠ Common exam trap
CompTIA CASP+ often tests the distinction between risk acceptance and risk transference, where candidates mistakenly classify outsourcing or insurance as acceptance rather than transference.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Obtaining senior management sign-off to accept the risk without additional controls.
Risk acceptance is a formal decision by management to acknowledge and accept a specific risk without implementing additional controls. This is typically documented in a risk register and signed off by senior leadership, indicating that the cost of mitigation outweighs the potential impact. Option D is correct because formally acknowledging residual risk after controls are implemented is also a form of risk acceptance, as the organization accepts the remaining risk that cannot be fully mitigated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Outsourcing the application hosting to a third party.
Why it's wrong here
Outsourcing is risk transference.
- ✓
Obtaining senior management sign-off to accept the risk without additional controls.
Why this is correct
Management sign-off is a documented acceptance.
- ✗
Purchasing cyber insurance to cover potential losses.
Why it's wrong here
Insurance is risk transference, not acceptance.
- ✓
Formally acknowledging the residual risk after controls are implemented.
Why this is correct
Acknowledging residual risk is a form of acceptance.
- ✗
Implementing an intrusion prevention system to reduce the likelihood of attacks.
Why it's wrong here
This is risk mitigation, not acceptance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.