Courseiva
mediumMultiple ChoiceObjective-mapped

CS0-003 Practice Question: After a risk assessment, a security analyst…

After a risk assessment, a security analyst recommends accepting a low-risk finding. The system owner disagrees. Which communication strategy should the analyst use?

⚠ Common exam trap

Candidates often choose immediate escalation (A) or policy insistence (D) because they confuse risk acceptance with risk avoidance, failing to recognize that data-driven justification is the standard professional approach for resolving such disagreements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Present the risk assessment data and cost-benefit analysis to justify acceptance

The security analyst should use data-driven communication to resolve disagreements over risk acceptance. By presenting the risk assessment data and a cost-benefit analysis, the analyst provides objective evidence that the low-risk finding does not warrant mitigation, aligning with the NIST risk management framework's emphasis on informed decision-making. This approach respects the system owner's concerns while justifying the acceptance based on technical and business rationale.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Escalate the disagreement to the CISO immediately

    Why it's wrong here

    Escalating to the CISO immediately bypasses crucial steps in conflict resolution and stakeholder engagement, potentially damaging professional relationships. A security analyst's primary role is to present objective data and facilitate informed discussions, not to prematurely escalate disagreements before attempting to reach a consensus or clarify misunderstandings with the system owner. Such an action can undermine the collaborative nature of effective risk management within an organization.

  • Agree with the system owner and change the recommendation

    Why it's wrong here

    Agreeing with the system owner and unilaterally changing a recommendation without a data-driven re-evaluation fundamentally compromises the integrity and objectivity of the entire risk assessment process. This action undermines the security analyst's professional responsibility to provide unbiased, evidence-based findings, potentially leading to unaddressed vulnerabilities or misallocated resources. It sets a dangerous precedent where subjective preferences override established risk management methodologies.

  • Present the risk assessment data and cost-benefit analysis to justify acceptance

    Why this is correct

    Presenting the comprehensive risk assessment data, including the identified threats, vulnerabilities, likelihood, and impact, alongside a detailed cost-benefit analysis for various treatment options, is the most effective approach. This allows stakeholders, including the system owner, to make an informed, data-driven decision regarding risk acceptance, ensuring transparency and alignment with business objectives. It facilitates a collaborative understanding of why acceptance is the appropriate strategy, based on objective facts rather than subjective opinions.

  • Insist that the finding must be mitigated due to policy

    Why it's wrong here

    Insisting solely on mitigation due to policy, without considering the specific business context or the full spectrum of risk treatment options, demonstrates an inflexible approach to risk management. While policies are critical, a mature risk framework acknowledges that risk acceptance is a valid and often necessary strategy when mitigation costs outweigh potential impacts or when residual risk is within acceptable thresholds. This rigid stance ignores the practical realities of business operations and the need for a balanced, risk-informed decision.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.