Courseiva
Security Principles →hardMultiple Choice

ISC2 CC Security Principles Practice Question

A company is evaluating a new cloud service provider. As part of due diligence, they review the provider's security certifications, conduct a site visit, and check references. This process is an example of which risk management strategy?

⚠ Common exam trap

CC often tests due diligence vs. risk mitigation — candidates see 'reviewing certifications' and pick mitigation, but investigation before a decision is due diligence, while mitigation is the control implementation that follows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Due diligence

Reviewing a provider's security certifications, conducting a site visit, and checking references are all investigative activities performed before committing to a relationship — this is the definition of due diligence. Due diligence is the assessment phase of risk management that gathers evidence to inform a risk decision. It is distinct from mitigation (implementing controls), transfer (shifting risk via insurance/contracts), and acceptance (acknowledging risk without action).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk acceptance

    Why it's wrong here

    Acceptance means acknowledging a risk and proceeding without additional controls. Due diligence actively gathers evidence to lower uncertainty before onboarding, so it changes the risk position rather than tolerating it. Acceptance fits low-impact risks where the cost of treatment exceeds the potential loss.

  • ✗

    Risk mitigation

    Why it's wrong here

    Mitigation reduces risk likelihood or impact through controls; due diligence here is assessment, not treatment. It is tempting because vetting feels like a safeguard, yet no control is applied to the provider's environment. Mitigation would be correct if the company enforced encryption, access restrictions or contractual security requirements.

  • ✓

    Due diligence

    Why this is correct

    Due diligence is the investigative process of verifying a provider's claims before contracting, exactly matching the site visits, certification reviews and reference checks described. It satisfies the stem's requirement to assess risk through pre-engagement scrutiny rather than transferring, avoiding or accepting it.

  • ✗

    Risk transfer

    Why it's wrong here

    Risk transfer shifts financial impact to a third party, typically via insurance or contractual indemnity. Reviewing certifications, visiting sites and checking references reduce uncertainty about the provider itself. Transfer would apply when purchasing cyber insurance or negotiating liability clauses, not when assessing a vendor's controls.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.