CAS-004 Governance, Risk, and Compliance Practice Question
An organization has implemented a risk treatment plan that includes purchasing cyber insurance for potential data breach costs. Which risk treatment option does this represent?
⚠ Common exam trap
It's easy for candidates to confuse risk transfer with risk mitigation, as both involve taking action; candidates may think insurance reduces risk, but it only shifts financial impact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk transfer
Purchasing cyber insurance transfers the financial consequences of a data breach to a third-party insurer, which is the definition of risk transfer. The organization does not eliminate the risk or reduce its likelihood — it shifts the monetary impact to another party. This is a classic example of risk transfer in risk treatment planning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk mitigation
Why it's wrong here
Insurance transfers the financial consequence of a breach to a third party rather than reducing likelihood or impact, so it is risk transference. It is tempting because insurance is arranged alongside controls, yet mitigation means implementing safeguards that lower the risk itself.
- ✗
Risk avoidance
Why it's wrong here
Avoidance eliminates the activity or asset generating the risk entirely; buying insurance retains the risk and compensates losses, which is transference. It is tempting because both are treatment options, yet avoidance would mean ceasing the data processing that creates breach exposure.
- ✗
Risk acceptance
Why it's wrong here
Insurance transfers the financial consequence of a breach to a third party, which is risk transference, not acceptance. Acceptance means retaining the risk with no mitigating action, which would be the answer if the organisation simply documented the exposure and set aside no controls or cover.
- ✓
Risk transfer
Why this is correct
Purchasing cyber insurance shifts the financial consequence of a data breach to an insurer rather than eliminating or reducing the risk itself. This is risk transfer, matching the treatment plan's intent to cover potential breach costs through a third party.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.