Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

An organization has implemented a risk treatment plan that includes purchasing cyber insurance for potential data breach costs. Which risk treatment option does this represent?

⚠ Common exam trap

It's easy for candidates to confuse risk transfer with risk mitigation, as both involve taking action; candidates may think insurance reduces risk, but it only shifts financial impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk transfer

Purchasing cyber insurance transfers the financial consequences of a data breach to a third-party insurer, which is the definition of risk transfer. The organization does not eliminate the risk or reduce its likelihood — it shifts the monetary impact to another party. This is a classic example of risk transfer in risk treatment planning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk mitigation

    Why it's wrong here

    Insurance transfers the financial consequence of a breach to a third party rather than reducing likelihood or impact, so it is risk transference. It is tempting because insurance is arranged alongside controls, yet mitigation means implementing safeguards that lower the risk itself.

  • ✗

    Risk avoidance

    Why it's wrong here

    Avoidance eliminates the activity or asset generating the risk entirely; buying insurance retains the risk and compensates losses, which is transference. It is tempting because both are treatment options, yet avoidance would mean ceasing the data processing that creates breach exposure.

  • ✗

    Risk acceptance

    Why it's wrong here

    Insurance transfers the financial consequence of a breach to a third party, which is risk transference, not acceptance. Acceptance means retaining the risk with no mitigating action, which would be the answer if the organisation simply documented the exposure and set aside no controls or cover.

  • ✓

    Risk transfer

    Why this is correct

    Purchasing cyber insurance shifts the financial consequence of a data breach to an insurer rather than eliminating or reducing the risk itself. This is risk transfer, matching the treatment plan's intent to cover potential breach costs through a third party.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.