CAS-004 Governance, Risk, and Compliance Practice Question
After a risk assessment, a company identifies that the residual risk for a critical application is higher than the risk appetite. The risk owner proposes implementing additional controls to reduce the risk further. Which risk treatment option does this represent?
⚠ Common exam trap
Many exam-takers confuse risk mitigation with risk acceptance or avoidance, especially when the scenario mentions residual risk exceeding appetite; candidates might think acceptance is implied, but the proposal of additional controls clearly indicates mitigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk mitigation
Risk mitigation involves implementing additional controls to reduce the likelihood or impact of a risk. Since the residual risk exceeds the risk appetite, the risk owner proposes further controls to lower it, which is the definition of risk mitigation. This aligns with the goal of bringing risk within acceptable limits.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk transfer
Why it's wrong here
Transferring risk shifts financial impact to a third party, typically via insurance or outsourcing, without altering the underlying likelihood or severity. Adding controls to lower residual risk is mitigation. Transfer suits scenarios where a counterparty can absorb consequences the organisation prefers not to retain.
- ✓
Risk mitigation
Why this is correct
Adding controls to lower residual risk below the risk appetite is risk mitigation: the organisation reduces likelihood or impact rather than avoiding, transferring or accepting the risk. The risk owner's proposal modifies the risk itself, matching mitigation.
- ✗
Risk acceptance
Why it's wrong here
Acceptance means tolerating residual risk without further action, which contradicts a risk owner actively proposing new controls because residual risk exceeds appetite. Acceptance is valid only when risk falls within appetite or when treatment cost outweighs benefit.
- ✗
Risk avoidance
Why it's wrong here
Avoidance eliminates the activity or asset generating the risk entirely, such as discontinuing a service. Implementing controls to reduce risk while continuing the critical application is mitigation, not avoidance. Avoidance fits scenarios where no control can bring risk within appetite.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.