mediumMultiple ChoiceObjective-mapped
CS0-003 Practice Question: After a risk assessment, a security analyst…
After a risk assessment, a security analyst recommends accepting a low-risk finding. The system owner disagrees. Which communication strategy should the analyst use?
⚠ Common exam trap
Candidates often choose immediate escalation (A) or policy insistence (D) because they confuse risk acceptance with risk avoidance, failing to recognize that data-driven justification is the standard professional approach for resolving such disagreements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Present the risk assessment data and cost-benefit analysis to justify acceptance
The security analyst should use data-driven communication to resolve disagreements over risk acceptance. By presenting the risk assessment data and a cost-benefit analysis, the analyst provides objective evidence that the low-risk finding does not warrant mitigation, aligning with the NIST risk management framework's emphasis on informed decision-making. This approach respects the system owner's concerns while justifying the acceptance based on technical and business rationale.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Escalate the disagreement to the CISO immediately
Why it's wrong here
Escalating to the CISO immediately bypasses crucial steps in conflict resolution and stakeholder engagement, potentially damaging professional relationships. A security analyst's primary role is to present objective data and facilitate informed discussions, not to prematurely escalate disagreements before attempting to reach a consensus or clarify misunderstandings with the system owner. Such an action can undermine the collaborative nature of effective risk management within an organization.
- ✗
Agree with the system owner and change the recommendation
Why it's wrong here
Agreeing with the system owner and unilaterally changing a recommendation without a data-driven re-evaluation fundamentally compromises the integrity and objectivity of the entire risk assessment process. This action undermines the security analyst's professional responsibility to provide unbiased, evidence-based findings, potentially leading to unaddressed vulnerabilities or misallocated resources. It sets a dangerous precedent where subjective preferences override established risk management methodologies.
- ✓
Present the risk assessment data and cost-benefit analysis to justify acceptance
Why this is correct
Presenting the comprehensive risk assessment data, including the identified threats, vulnerabilities, likelihood, and impact, alongside a detailed cost-benefit analysis for various treatment options, is the most effective approach. This allows stakeholders, including the system owner, to make an informed, data-driven decision regarding risk acceptance, ensuring transparency and alignment with business objectives. It facilitates a collaborative understanding of why acceptance is the appropriate strategy, based on objective facts rather than subjective opinions.
- ✗
Insist that the finding must be mitigated due to policy
Why it's wrong here
Insisting solely on mitigation due to policy, without considering the specific business context or the full spectrum of risk treatment options, demonstrates an inflexible approach to risk management. While policies are critical, a mature risk framework acknowledges that risk acceptance is a valid and often necessary strategy when mitigation costs outweigh potential impacts or when residual risk is within acceptable thresholds. This rigid stance ignores the practical realities of business operations and the need for a balanced, risk-informed decision.
Visual reference
Go deeper
Related to this question
Learn chapter
SIEM Log Analysis
Key term
Mitigation
Mitigation is the process of reducing the severity, impact, or likelihood of a security threat or vulnerability.
Key term
Risk acceptance
Risk acceptance is a risk management strategy where an organization acknowledges a potential risk but decides to tolerate it without taking active measures to reduce or eliminate it.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.