hardMultiple Choice
CS0-003 Practice Question: Risk acceptance requires formal documentation.
A business owner accepts delayed remediation for a production system. What must the report include? If the primary audience is business service owner, which content choice is most appropriate?
⚠ Common exam trap
The CS0-004 exam often tests the misconception that risk acceptance means the risk is simply ignored or not reported, but the correct approach is to formally document the acceptance with all required metadata to maintain accountability and audit readiness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk owner, reason, compensating controls, review date, and expiry
When a business owner accepts delayed remediation for a production system, the report must formally document the risk acceptance decision. This includes the risk owner (who accepted the risk), the reason for acceptance, any compensating controls in place, a review date to reassess the risk, and an expiry date for the acceptance. This aligns with risk management frameworks like NIST SP 800-37 and ISO 27005, which require traceability and accountability for accepted risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Only the analyst's personal opinion
Why it's wrong here
An analyst's personal opinion, while valuable for initial assessment, lacks the formal authority and business context required for a definitive risk acceptance decision. Risk acceptance is a strategic business choice, not merely a technical recommendation, and must be owned by an individual with accountability for the business impact. Relying solely on an analyst's view bypasses the necessary governance and accountability structures for managing organizational risk.
- ✓
Risk owner, reason, compensating controls, review date, and expiry
Why this is correct
Proper risk acceptance necessitates a comprehensive record including the designated risk owner, a clear justification for acceptance, and any implemented compensating controls to mitigate residual exposure. Furthermore, specifying a definite review date and an ultimate expiry ensures the decision remains time-bound and subject to re-evaluation as threat landscapes or business contexts evolve. This structured approach ensures accountability, transparency, and proactive management of accepted risks within the organization.
- ✗
No mention of the accepted risk
Why it's wrong here
Omitting any mention of an accepted risk from formal documentation creates a critical blind spot within the organization's risk register and governance framework. This lack of transparency prevents stakeholders from understanding the true risk posture, hindering informed decision-making and potentially leading to unmanaged exposure. Without proper documentation, accountability for the accepted risk becomes ambiguous, undermining effective risk management practices.
- ✗
A permanent exception with no review
Why it's wrong here
Granting a permanent exception without any scheduled review introduces significant long-term risk, as the underlying conditions, threat landscape, or control effectiveness can change over time. Such an indefinite acceptance fails to account for evolving business requirements or new vulnerabilities, potentially leaving the organization exposed to unmanaged threats. Effective risk management demands periodic re-evaluation of all accepted risks to ensure their continued validity and appropriateness.
Go deeper
Related to this question
Learn chapter
Business Email Compromise (BEC) Response
Key term
Risk management
Risk management is the process of identifying, assessing, and controlling threats to an organization's capital, earnings, and operations, including IT systems and data.
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.