mediumMultiple Choice
Risk Response Strategies — When to Accept Risk
An organization's risk register contains a risk with a very high impact but very low likelihood. The risk response strategy should be:
Quick Answer
The answer is to accept the risk. This is the correct risk response strategy because when a risk has very high impact but very low likelihood, the cost of mitigation, avoidance, or transfer would almost certainly exceed the expected benefit, making acceptance the most cost-effective and aligned choice with the organization’s risk appetite. On the Certified in Risk and Information Systems Control CRISC exam, this scenario tests your understanding of cost-benefit analysis within risk response strategies; a common trap is to choose “mitigate” due to the high impact, but the key is the extremely low probability. A useful memory tip is to think of the “low probability, high impact” pairing as a “black swan” event—you acknowledge it exists and monitor it, but you do not spend resources trying to prevent the nearly impossible.
⚠ Common exam trap
The trap here is that candidates mistakenly choose 'Mitigate' or 'Transfer' for any high-impact risk, failing to weigh the low likelihood against the cost of the response, which is a core concept in risk treatment decisions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accept
When a risk has very high impact but very low likelihood, the most cost-effective response is often acceptance, because the probability of occurrence is so low that the cost of mitigation, avoidance, or transfer would exceed the expected benefit. Accepting the risk means the organization formally acknowledges it and monitors it, but does not allocate resources to reduce or transfer it. This aligns with the principle of risk appetite and cost-benefit analysis in IT risk management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mitigate
Why it's wrong here
Mitigation might not be cost-justified.
- ✗
Avoid
Why it's wrong here
Avoidance eliminates the activity generating the risk entirely, which is excessive when likelihood is very low and the activity may be core to the business. Avoidance is correct when impact is severe and likelihood cannot be reduced to an acceptable level through other means.
- ✗
Transfer
Why it's wrong here
Transferring a very-low-likelihood risk usually costs more in premiums than the expected loss justifies, and residual accountability stays with the organisation. It suits high-frequency, high-severity risks where insurance or outsourcing genuinely absorbs the financial impact.
- ✓
Accept
Why this is correct
Very low likelihood combined with very high impact does not justify the cost of avoidance, transfer or mitigation. Acceptance is appropriate because the expected loss is small, though the risk should still be monitored and a contingency plan retained.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CRISC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE of the following are effective risk treatment strategies?
hard- A.Accept the risk without any analysis
- ✓ B.Avoid the risk by discontinuing the activity
- C.Ignore the risk if it has not materialized yet
- ✓ D.Implement compensating controls to reduce risk
- ✓ E.Transfer the risk through outsourcing
Why B: Option B is correct because risk avoidance is a recognized treatment strategy in which the organization eliminates the risk entirely by discontinuing the activity or process that generates it. Option D is correct because implementing compensating controls is a form of risk mitigation/reduction, lowering the likelihood or impact of a threat to an acceptable level. Option E is correct because risk transfer shifts the financial or operational impact of a risk to a third party, such as through outsourcing, insurance, or contractual agreements. Option A is not a valid treatment because accepting a risk must be a deliberate, informed decision based on analysis, not done blindly without assessment. Option C is not a valid treatment because ignoring a risk simply leaves it unmanaged and does not constitute an accepted risk-management strategy.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.