Drag a concept onto its matching description — or click a concept then click the description.
Accept
Mitigate
Transfer
Avoid
Match each business scenario to the most appropriate risk treatment. 1. A legacy reporting server is expensive to replace, and leadership is willing to monitor the low expected loss for now. 2. A public web portal is being hit by credential stuffing, so the team adds MFA and rate limiting. 3. The organization wants protection from a costly third-party outage by purchasing cyber insurance. 4. A proposed project would collect regulated data that the business has decided not to process at all.
Drag a concept onto its matching description — or click a concept then click the description.
Accept
Mitigate
Transfer
Avoid
Answer choices
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Risk acceptance: A legacy reporting server is expensive to replace, and leadership is willing to monitor the low expected loss for now.
Risk acceptance acknowledges the risk without action; mitigation reduces risk via controls; transfer shifts risk to insurance; avoidance eliminates the risk activity; reduction and sharing are related but less direct matches to the scenarios.
Answer analysis
For each option: why learners choose it and why it is or isn't the right answer here.
Risk acceptance: A legacy reporting server is expensive to replace, and leadership is willing to monitor the low expected loss for now.
Why this is correct
Risk acceptance is appropriate when the cost of controls exceeds the potential loss. Here, replacing the legacy server is expensive, and leadership chooses to monitor the expected low loss without investing in remediation. This is a deliberate, documented decision to tolerate residual risk, typically accompanied by ongoing monitoring and periodic review.
Risk mitigation: A public web portal is being hit by credential stuffing, so the team adds MFA and rate limiting.
Why this is correct
Credential stuffing relies on reused passwords and automated attempts to gain unauthorized access. Adding multi-factor authentication (MFA) and rate limiting directly reduces the likelihood of a successful attack and limits the impact of compromised credentials. Implementing these technical controls is a classic risk mitigation strategy because it changes the characteristics of the risk rather than transferring or avoiding it.
Risk transfer: The organization wants protection from a costly third-party outage by purchasing cyber insurance.
Why this is correct
A third-party outage could introduce significant financial losses, such as business interruption or recovery costs. Purchasing cyber insurance transfers the financial risk to the insurer, meaning the organization retains the operational risk but shifts the monetary impact. This is risk transfer, a risk financing technique that uses a contractual arrangement to share potential losses.
Risk avoidance: A proposed project would collect regulated data that the business has decided not to process at all.
Why this is correct
Regulated data such as PII or protected health information imposes strict compliance obligations. By deciding not to process the data at all, the organization eliminates the legal, reputational, and security risks associated with that data. This is risk avoidance because the activity itself is abandoned, ensuring no risk from that source exists.
Risk acceptance: A proposed project would collect regulated data that the business has decided not to process.
Why it's wrong here
This scenario is not risk acceptance because acceptance implies tolerating a known risk without eliminating it. Here, the business refuses to process regulated data at all, which completely removes the risk from the organization's risk register. The correct classification is risk avoidance, as the risk is neutralized by not engaging in the risky activity.
Risk mitigation: The organization wants protection from a costly third-party outage by purchasing cyber insurance.
Why it's wrong here
Risk mitigation involves implementing controls to reduce the probability or severity of a risk. Purchasing cyber insurance does not reduce the likelihood of a third-party outage or its operational impact; it only shifts the financial burden to an insurer. Therefore, this action is risk transfer, not mitigation, as the organization retains the risk source but not the full financial consequences.
Go deeper
Learn chapter
Risk Management Concepts
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
Key term
Credential stuffing
Credential stuffing is a cyberattack where attackers use lists of stolen usernames and passwords to gain unauthorized access to user accounts on different websites.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.