CAS-004 Governance, Risk, and Compliance Practice Question
An organization has identified a vulnerability in a legacy system that cannot be patched. The system is critical for operations, and the cost of mitigating the vulnerability exceeds the potential loss. Which risk treatment option is most appropriate?
⚠ Common exam trap
CAS-005 often tests the confusion between risk acceptance and risk avoidance when a system is critical — candidates must recognize that acceptance is chosen when the system must remain operational and mitigation is infeasible or cost-prohibitive, whereas avoidance requires eliminating the activity entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk acceptance
Risk acceptance is the appropriate treatment when a vulnerability cannot be mitigated (legacy system, no patch available), the system is critical to operations (so avoidance is not feasible), and the cost of mitigation exceeds the potential loss. The organization formally acknowledges the residual risk and documents the decision, often with compensating controls and management sign-off. This is a deliberate, documented business decision rather than neglect.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Risk acceptance
Why this is correct
Acceptance fits because the legacy system cannot be patched, remains operationally critical, and the mitigation cost exceeds the potential loss. Retaining the residual risk formally, with documented sign-off and monitoring, is the proportionate treatment rather than transfer, avoidance or further mitigation.
- ✗
Risk avoidance
Why it's wrong here
Avoidance means eliminating the activity or system entirely, which the stem rules out because the legacy system is critical for operations. It is tempting because avoidance fully removes the risk, and it would be correct if the business process could be discontinued or replaced without operational impact.
- ✗
Risk mitigation
Why it's wrong here
Mitigation reduces likelihood or impact through controls, but the stem states mitigation cost exceeds the potential loss, so spending on it is not justified. Mitigation is correct when cost-effective controls exist; here the organisation instead accepts the residual risk because the system cannot be patched.
- ✗
Risk transfer
Why it's wrong here
Transfer shifts financial impact via insurance or contracts but cannot transfer the underlying unpatched vulnerability, and the stem frames the decision as accepting exposure because mitigation costs exceed potential loss. Transfer suits risks with quantifiable third-party liability, not an operational system whose loss the organisation must absorb.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.