Drag a concept onto its matching description — or click a concept then click the description.
Accept risk
Mitigate risk
Transfer risk
Avoid risk
Match each business situation to the best risk treatment. Use each treatment once.
Drag a concept onto its matching description — or click a concept then click the description.
Accept risk
Mitigate risk
Transfer risk
Avoid risk
Answer choices
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Minor error with low probability: Accept
Risk treatment decisions are based on likelihood and impact: accept low risks, avoid high-high risks, mitigate medium risks, and transfer risks that are high likelihood but low impact or low likelihood but high impact.
Answer analysis
For each option: why learners choose it and why it is or isn't the right answer here.
Minor error with low probability: Accept
Why this is correct
Low-likelihood and low-impact risks are deemed to have negligible annualized loss expectancy, making the cost of any safeguard greater than the expected loss reduction. Both mitigation and transfer add unnecessary expense and overhead, so the loss is simply incorporated as a routine operating cost. Acceptance requires a conscious, documented decision and often monitoring to ensure the risk remains low.
Catastrophic event with high probability: Avoid
Why this is correct
Catastrophic impact with high likelihood places the risk far above the organization's risk tolerance, and no effective controls can economically lower it to an acceptable residual level. Elimination of the activity, process, or product is the only treatment that removes the exposure completely. This strategy is deliberately chosen over mitigation because even 'reduced' catastrophic risk is still unacceptable and could threaten the organization's survival.
Moderate risk with medium likelihood and impact: Mitigate
Why this is correct
With both medium likelihood and medium impact, the risk does not warrant full avoidance but cannot be left squarely at its natural level. Applying targeted controls—such as redundant systems, security hardening, or procedural defenses—lowers the probability or impact to an acceptable threshold. Mitigation preserves some of the activity's benefits while keeping the residual risk within the organization's stated risk appetite.
Low probability but severe damage: Transfer
Why this is correct
Severe damage despite low probability creates a situation where insurance or contractual transfer is cost-effective because the risk premium is small relative to the catastrophic potential loss. Transfer shifts the financial consequence to a third party, such as through a cyber insurance policy or a managed service contract, but does not reduce the probability. This treatment is especially appropriate when the organization cannot feasibly control the rare event and cannot accept the severe financial impact.
Minor error with low probability: Transfer
Why it's wrong here
Applying transfer to a minor, low-probability risk is economically illogical because the cost of moving the risk—premiums, fees, or contract overhead—will outweigh the trivial expected loss. The entire purpose of transfer is to protect against severe, uncommon losses, not routine negligible ones. Thus, it would waste resources that could be better spent elsewhere, making acceptance the only defensible treatment.
Catastrophic event with high probability: Mitigate
Why it's wrong here
Catastrophic high-probability events cannot be effectively mitigated because even strong controls will leave an enormous residual risk that remains outside the organization's tolerance. Mitigation implies accepting some level of remaining exposure, yet for this risk that exposure could still lead to enterprise-wide failure. Avoidance, by discontinuing or redesigning the activity, is required to eliminate the exposure entirely rather than merely reduce it.
Go deeper
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.