A vulnerability assessment reveals that a legacy system has unpatched software. The organization decides to accept the risk because the system is isolated and has compensating controls. This decision is an example of:
Risk acceptance means acknowledging a risk and choosing to bear its potential impact without further mitigation, which matches the decision to tolerate the unpatched legacy system because isolation and compensating controls reduce exposure to an acceptable level.
Why this answer
Risk acceptance means the organization acknowledges the risk and chooses to retain it without taking further action, often because the cost of mitigation outweighs the potential impact or because compensating controls reduce it to an acceptable level. Here, the legacy system is isolated with compensating controls, so the organization formally accepts the residual risk.
Exam trap
CC often tests the distinction between acceptance and mitigation; candidates see 'compensating controls' and pick mitigation, but the key phrase is 'decides to accept the risk' — the controls justify acceptance, not further action.
How to eliminate wrong answers
Option A is wrong because risk avoidance means eliminating the activity or system that introduces the risk entirely, not keeping it. Option C is wrong because risk mitigation involves implementing controls to reduce the likelihood or impact, which the organization has already done via isolation and compensating controls; the decision to not do more is acceptance. Option D is wrong because risk transfer shifts the risk to a third party, such as through insurance or outsourcing, which is not described here.