mediumMultiple ChoiceObjective-mapped
Risk Response Strategies — When to Accept Risk
An organization's risk register contains a risk with a very high impact but very low likelihood. The risk response strategy should be:
Quick Answer
The answer is to accept the risk. This is the correct risk response strategy because when a risk has very high impact but very low likelihood, the cost of mitigation, avoidance, or transfer would almost certainly exceed the expected benefit, making acceptance the most cost-effective and aligned choice with the organization’s risk appetite. On the Certified in Risk and Information Systems Control CRISC exam, this scenario tests your understanding of cost-benefit analysis within risk response strategies; a common trap is to choose “mitigate” due to the high impact, but the key is the extremely low probability. A useful memory tip is to think of the “low probability, high impact” pairing as a “black swan” event—you acknowledge it exists and monitor it, but you do not spend resources trying to prevent the nearly impossible.
⚠ Common exam trap
The trap here is that candidates mistakenly choose 'Mitigate' or 'Transfer' for any high-impact risk, failing to weigh the low likelihood against the cost of the response, which is a core concept in risk treatment decisions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accept
When a risk has very high impact but very low likelihood, the most cost-effective response is often acceptance, because the probability of occurrence is so low that the cost of mitigation, avoidance, or transfer would exceed the expected benefit. Accepting the risk means the organization formally acknowledges it and monitors it, but does not allocate resources to reduce or transfer it. This aligns with the principle of risk appetite and cost-benefit analysis in IT risk management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mitigate
Why it's wrong here
Mitigation might not be cost-justified.
- ✗
Avoid
Why it's wrong here
Avoidance eliminates the activity, which may not be necessary.
- ✗
Transfer
Why it's wrong here
Transfer may be costly for low-likelihood risks.
- ✓
Accept
Why this is correct
Acceptance is common for low-likelihood, high-impact risks.
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CRISC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE of the following are effective risk treatment strategies?
hard- A.Accept the risk without any analysis
- ✓ B.Avoid the risk by discontinuing the activity
- C.Ignore the risk if it has not materialized yet
- ✓ D.Implement compensating controls to reduce risk
- ✓ E.Transfer the risk through outsourcing
Why B: Avoiding risk by discontinuing the activity is a recognized risk treatment strategy under the ISACA Risk IT framework. By ceasing the activity that introduces the risk, the organization eliminates the possibility of the risk event occurring, which is a valid and often necessary response when the risk exceeds the organization's risk appetite and cannot be cost-effectively mitigated or transferred.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.