Courseiva
mediumMultiple Choice

CAS-004 Practice Question: Is evaluating risk treatment options for a…

An organization is evaluating risk treatment options for a critical vulnerability with a CVSS score of 9.8. The cost to remediate is $500,000, and the potential loss if exploited is estimated at $2,000,000. Which risk response is most appropriate?

⚠ Common exam trap

CompTIA often tests the misconception that a high CVSS score automatically justifies acceptance or transfer, but the key is comparing the cost of remediation against the potential loss to determine the most appropriate risk response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remediate the vulnerability

With a CVSS score of 9.8 (critical) and a potential loss of $2,000,000, the cost to remediate ($500,000) is significantly lower than the expected loss. Remediation reduces the risk to an acceptable residual level, making it the most cost-effective response. This aligns with the principle that when the cost of remediation is less than the potential loss, the organization should directly fix the vulnerability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Transfer the risk through cyber insurance

    Why it's wrong here

    Insurance compensates financial loss but leaves the 9.8 vulnerability exploitable, so the $2,000,000 exposure and operational disruption remain. Transfer suits low-likelihood, high-impact risks that cannot be remediated; here remediation costs a quarter of the potential loss, so fixing it is the appropriate response.

  • ✗

    Accept the risk

    Why it's wrong here

    Acceptance leaves a 9.8 vulnerability exploitable, exposing the organisation to the full $2,000,000 loss when remediation costs only $500,000. Acceptance suits low-impact risks where treatment cost exceeds potential loss; here the arithmetic and severity both demand remediation.

  • ✗

    Avoid the risk by decommissioning the affected system

    Why it's wrong here

    Decommissioning removes the vulnerability but destroys the business capability the system delivers, a disproportionate response when a $500,000 patch addresses a $2,000,000 exposure. Avoidance is reserved for risks whose underlying activity cannot be made acceptable at any reasonable cost.

  • ✓

    Remediate the vulnerability

    Why this is correct

    Remediation costs $500,000 against a potential $2,000,000 loss, so the control is economically justified and eliminates the critical 9.8 vulnerability. This satisfies the stem's cost-benefit constraint, unlike acceptance, which retains unacceptable exposure, or transfer, which rarely covers exploited vulnerabilities.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.