Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

An organization's security policy defines that all sensitive data must be encrypted. However, a business unit has a legacy application that cannot support encryption without a major rewrite. The risk owner decides to accept the risk. This is an example of which risk treatment strategy?

⚠ Common exam trap

A common mix-up: candidates confuse risk acceptance with risk mitigation when a compensating control is mentioned, or assuming that any decision to not encrypt automatically means acceptance, while ignoring that the risk owner's formal acceptance is the key differentiator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk acceptance

Risk acceptance is the correct answer because the risk owner has decided to acknowledge the risk and continue operating without implementing additional controls. The legacy application cannot support encryption without a major rewrite, so the organization chooses to accept the risk rather than mitigate, transfer, or avoid it. This aligns with the definition of risk acceptance as a risk treatment strategy where no action is taken to reduce the risk, and the organization retains the potential consequences.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk acceptance

    Why this is correct

    Accepting the risk means the risk owner acknowledges the legacy application's exposure and proceeds without encryption, absorbing potential loss. This matches risk acceptance rather than mitigation, transfer or avoidance, satisfying the stem's decision to tolerate the identified risk.

  • ✗

    Risk mitigation

    Why it's wrong here

    Mitigation reduces risk through controls such as encryption, whereas the risk owner here chose to retain the exposure without adding controls. Mitigation would be correct had the organisation rewritten the application or deployed a compensating control.

  • ✗

    Risk transfer

    Why it's wrong here

    Risk transfer shifts financial impact to a third party through insurance or contractual indemnity; it does not apply when a risk owner simply accepts an unencrypted legacy application. It is tempting because cyber-insurance policies do transfer breach costs, which would be the correct choice had the business unit purchased a policy covering that exposure.

  • ✗

    Risk avoidance

    Why it's wrong here

    Risk avoidance means eliminating the activity or system that generates the risk, so it cannot satisfy a scenario where the legacy application continues running with the risk formally accepted. It is tempting because avoidance genuinely removes risk entirely, and would be correct if the business unit decommissioned the application or replaced it with an encrypting alternative.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.