Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

An organization has identified a vulnerability in a legacy system that cannot be patched. The system is critical for operations, and the cost of mitigating the vulnerability exceeds the potential loss. Which risk treatment option is most appropriate?

⚠ Common exam trap

CAS-005 often tests the confusion between risk acceptance and risk avoidance when a system is critical — candidates must recognize that acceptance is chosen when the system must remain operational and mitigation is infeasible or cost-prohibitive, whereas avoidance requires eliminating the activity entirely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk acceptance

Risk acceptance is the appropriate treatment when a vulnerability cannot be mitigated (legacy system, no patch available), the system is critical to operations (so avoidance is not feasible), and the cost of mitigation exceeds the potential loss. The organization formally acknowledges the residual risk and documents the decision, often with compensating controls and management sign-off. This is a deliberate, documented business decision rather than neglect.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk acceptance

    Why this is correct

    Acceptance fits because the legacy system cannot be patched, remains operationally critical, and the mitigation cost exceeds the potential loss. Retaining the residual risk formally, with documented sign-off and monitoring, is the proportionate treatment rather than transfer, avoidance or further mitigation.

  • ✗

    Risk avoidance

    Why it's wrong here

    Avoidance means eliminating the activity or system entirely, which the stem rules out because the legacy system is critical for operations. It is tempting because avoidance fully removes the risk, and it would be correct if the business process could be discontinued or replaced without operational impact.

  • ✗

    Risk mitigation

    Why it's wrong here

    Mitigation reduces likelihood or impact through controls, but the stem states mitigation cost exceeds the potential loss, so spending on it is not justified. Mitigation is correct when cost-effective controls exist; here the organisation instead accepts the residual risk because the system cannot be patched.

  • ✗

    Risk transfer

    Why it's wrong here

    Transfer shifts financial impact via insurance or contracts but cannot transfer the underlying unpatched vulnerability, and the stem frames the decision as accepting exposure because mitigation costs exceed potential loss. Transfer suits risks with quantifiable third-party liability, not an operational system whose loss the organisation must absorb.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.