Courseiva
hardMultiple Choice

CS0-003 Practice Question: Risk acceptance requires formal documentation.

A business owner accepts delayed remediation for a production system. What must the report include? If the primary audience is business service owner, which content choice is most appropriate?

⚠ Common exam trap

The CS0-004 exam often tests the misconception that risk acceptance means the risk is simply ignored or not reported, but the correct approach is to formally document the acceptance with all required metadata to maintain accountability and audit readiness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk owner, reason, compensating controls, review date, and expiry

When a business owner accepts delayed remediation for a production system, the report must formally document the risk acceptance decision. This includes the risk owner (who accepted the risk), the reason for acceptance, any compensating controls in place, a review date to reassess the risk, and an expiry date for the acceptance. This aligns with risk management frameworks like NIST SP 800-37 and ISO 27005, which require traceability and accountability for accepted risks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Only the analyst's personal opinion

    Why it's wrong here

    An analyst's personal opinion, while valuable for initial assessment, lacks the formal authority and business context required for a definitive risk acceptance decision. Risk acceptance is a strategic business choice, not merely a technical recommendation, and must be owned by an individual with accountability for the business impact. Relying solely on an analyst's view bypasses the necessary governance and accountability structures for managing organizational risk.

  • ✓

    Risk owner, reason, compensating controls, review date, and expiry

    Why this is correct

    Proper risk acceptance necessitates a comprehensive record including the designated risk owner, a clear justification for acceptance, and any implemented compensating controls to mitigate residual exposure. Furthermore, specifying a definite review date and an ultimate expiry ensures the decision remains time-bound and subject to re-evaluation as threat landscapes or business contexts evolve. This structured approach ensures accountability, transparency, and proactive management of accepted risks within the organization.

  • ✗

    No mention of the accepted risk

    Why it's wrong here

    Omitting any mention of an accepted risk from formal documentation creates a critical blind spot within the organization's risk register and governance framework. This lack of transparency prevents stakeholders from understanding the true risk posture, hindering informed decision-making and potentially leading to unmanaged exposure. Without proper documentation, accountability for the accepted risk becomes ambiguous, undermining effective risk management practices.

  • ✗

    A permanent exception with no review

    Why it's wrong here

    Granting a permanent exception without any scheduled review introduces significant long-term risk, as the underlying conditions, threat landscape, or control effectiveness can change over time. Such an indefinite acceptance fails to account for evolving business requirements or new vulnerabilities, potentially leaving the organization exposed to unmanaged threats. Effective risk management demands periodic re-evaluation of all accepted risks to ensure their continued validity and appropriateness.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.