Courseiva
Security Principles →mediumMultiple Select

ISC2 CC Security Principles Practice Question

A security analyst is reviewing the organization's risk management process. The analyst must identify which items are examples of risk treatment options. (Choose two.)

⚠ Common exam trap

The trap here is treating risk analysis activities, such as calculating loss expectancy, as if they were risk treatment decisions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Accepting the risk and documenting the decision

Risk treatment options include avoiding, mitigating, transferring, and accepting risk. Purchasing cyber insurance transfers financial risk to an insurer, while accepting and documenting risk is a conscious decision to tolerate it. Identifying vulnerabilities and calculating loss expectancy are assessment activities, and monitoring traffic is a control, so they are not treatment options themselves.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Calculating the annualized loss expectancy

    Why it's wrong here

    Calculating annualized loss expectancy is a quantitative risk analysis technique used to estimate potential financial loss. It supports decision-making but is not itself a treatment option. Treatment refers to the response selected, not the calculation used to inform that response, so this item is incorrect.

  • ✓

    Accepting the risk and documenting the decision

    Why this is correct

    Risk acceptance is a deliberate treatment choice where the organization decides the potential loss is tolerable and documents that decision. It is one of the standard risk treatment options, along with avoidance, mitigation, and transfer. Therefore, accepting and documenting the risk is a correct example.

  • ✗

    Identifying a vulnerability in a web application

    Why it's wrong here

    Identifying a vulnerability is part of risk assessment and analysis, not risk treatment. Treatment involves deciding what to do about the risk, such as avoiding, mitigating, transferring, or accepting it. Because this action only discovers the issue, it is not an example of a risk treatment option.

  • ✗

    Monitoring network traffic for anomalies

    Why it's wrong here

    Monitoring network traffic is a detective control that can support risk mitigation, but it is not one of the primary risk treatment categories. The treatment decision might be to mitigate, but the monitoring activity itself is an operational security function, not a treatment option. Thus it does not fit the requested examples.

  • ✓

    Transferring risk by purchasing cyber insurance

    Why this is correct

    Risk transfer shifts the financial impact of a risk to another party, often through insurance or contracts. Purchasing cyber insurance is a recognized risk treatment that compensates for losses but does not eliminate the threat itself. Therefore, it is a valid example of a risk treatment option in this scenario.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.