ISC2 CC Security Principles Practice Question
A security analyst is reviewing the organization's risk management process. The analyst must identify which items are examples of risk treatment options. (Choose two.)
⚠ Common exam trap
The trap here is treating risk analysis activities, such as calculating loss expectancy, as if they were risk treatment decisions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accepting the risk and documenting the decision
Risk treatment options include avoiding, mitigating, transferring, and accepting risk. Purchasing cyber insurance transfers financial risk to an insurer, while accepting and documenting risk is a conscious decision to tolerate it. Identifying vulnerabilities and calculating loss expectancy are assessment activities, and monitoring traffic is a control, so they are not treatment options themselves.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Calculating the annualized loss expectancy
Why it's wrong here
Calculating annualized loss expectancy is a quantitative risk analysis technique used to estimate potential financial loss. It supports decision-making but is not itself a treatment option. Treatment refers to the response selected, not the calculation used to inform that response, so this item is incorrect.
- ✓
Accepting the risk and documenting the decision
Why this is correct
Risk acceptance is a deliberate treatment choice where the organization decides the potential loss is tolerable and documents that decision. It is one of the standard risk treatment options, along with avoidance, mitigation, and transfer. Therefore, accepting and documenting the risk is a correct example.
- ✗
Identifying a vulnerability in a web application
Why it's wrong here
Identifying a vulnerability is part of risk assessment and analysis, not risk treatment. Treatment involves deciding what to do about the risk, such as avoiding, mitigating, transferring, or accepting it. Because this action only discovers the issue, it is not an example of a risk treatment option.
- ✗
Monitoring network traffic for anomalies
Why it's wrong here
Monitoring network traffic is a detective control that can support risk mitigation, but it is not one of the primary risk treatment categories. The treatment decision might be to mitigate, but the monitoring activity itself is an operational security function, not a treatment option. Thus it does not fit the requested examples.
- ✓
Transferring risk by purchasing cyber insurance
Why this is correct
Risk transfer shifts the financial impact of a risk to another party, often through insurance or contracts. Purchasing cyber insurance is a recognized risk treatment that compensates for losses but does not eliminate the threat itself. Therefore, it is a valid example of a risk treatment option in this scenario.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.