ISC2 CC Security Principles Practice Question
A vulnerability assessment reveals that a legacy system has unpatched software. The organization decides to accept the risk because the system is isolated and has compensating controls. This decision is an example of:
⚠ Common exam trap
CC often tests the distinction between acceptance and mitigation; candidates see 'compensating controls' and pick mitigation, but the key phrase is 'decides to accept the risk' — the controls justify acceptance, not further action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk acceptance
Risk acceptance means the organization acknowledges the risk and chooses to retain it without taking further action, often because the cost of mitigation outweighs the potential impact or because compensating controls reduce it to an acceptable level. Here, the legacy system is isolated with compensating controls, so the organization formally accepts the residual risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk avoidance
Why it's wrong here
Avoidance eliminates the activity or system generating the risk; here the legacy system stays running with compensating controls, so the exposure is retained, not removed. It is tempting because avoidance genuinely applies when an organisation retires or decommissions the vulnerable asset entirely, which is the correct choice when the risk cannot be tolerated at all.
- ✓
Risk acceptance
Why this is correct
Risk acceptance means acknowledging a risk and choosing to bear its potential impact without further mitigation, which matches the decision to tolerate the unpatched legacy system because isolation and compensating controls reduce exposure to an acceptable level.
- ✗
Risk mitigation
Why it's wrong here
Mitigation applies additional controls to reduce likelihood or impact; the stem already cites compensating controls, and the stated decision is to retain the residual risk rather than reduce it further. It is tempting because mitigation genuinely applies when new safeguards are implemented specifically to lower the risk to an acceptable level.
- ✗
Risk transfer
Why it's wrong here
Transfer shifts financial impact to a third party through insurance or contracts; no such arrangement appears here, and the organisation retains the exposure itself. It is tempting because transfer genuinely applies when an insurer or outsourced provider absorbs the loss, which is the correct choice when the organisation cannot bear the cost alone.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Risk acceptance
Risk acceptance is a risk management strategy where an organization acknowledges a potential risk but decides to tolerate it without taking active measures to reduce or eliminate it.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.