CAS-004 Governance, Risk, and Compliance Practice Question
An organization's security policy defines that all sensitive data must be encrypted. However, a business unit has a legacy application that cannot support encryption without a major rewrite. The risk owner decides to accept the risk. This is an example of which risk treatment strategy?
⚠ Common exam trap
A common mix-up: candidates confuse risk acceptance with risk mitigation when a compensating control is mentioned, or assuming that any decision to not encrypt automatically means acceptance, while ignoring that the risk owner's formal acceptance is the key differentiator.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk acceptance
Risk acceptance is the correct answer because the risk owner has decided to acknowledge the risk and continue operating without implementing additional controls. The legacy application cannot support encryption without a major rewrite, so the organization chooses to accept the risk rather than mitigate, transfer, or avoid it. This aligns with the definition of risk acceptance as a risk treatment strategy where no action is taken to reduce the risk, and the organization retains the potential consequences.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Risk acceptance
Why this is correct
Accepting the risk means the risk owner acknowledges the legacy application's exposure and proceeds without encryption, absorbing potential loss. This matches risk acceptance rather than mitigation, transfer or avoidance, satisfying the stem's decision to tolerate the identified risk.
- ✗
Risk mitigation
Why it's wrong here
Mitigation reduces risk through controls such as encryption, whereas the risk owner here chose to retain the exposure without adding controls. Mitigation would be correct had the organisation rewritten the application or deployed a compensating control.
- ✗
Risk transfer
Why it's wrong here
Risk transfer shifts financial impact to a third party through insurance or contractual indemnity; it does not apply when a risk owner simply accepts an unencrypted legacy application. It is tempting because cyber-insurance policies do transfer breach costs, which would be the correct choice had the business unit purchased a policy covering that exposure.
- ✗
Risk avoidance
Why it's wrong here
Risk avoidance means eliminating the activity or system that generates the risk, so it cannot satisfy a scenario where the legacy application continues running with the risk formally accepted. It is tempting because avoidance genuinely removes risk entirely, and would be correct if the business unit decommissioned the application or replaced it with an encrypting alternative.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.