Courseiva
Security Principles →hardMultiple Choice

ISC2 CC Security Principles Practice Question

An organization decides to accept the risk of using a legacy system that cannot be patched due to critical business operations. This is an example of:

⚠ Common exam trap

A common mix-up: candidates confuse risk acceptance with risk mitigation or avoidance, especially when the scenario mentions 'cannot be patched'—candidates might think that doing nothing is negligence, but in risk management, a documented decision to accept is a valid strategy. The exam often tests whether you recognize that acceptance is a conscious choice, not a failure to act.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk acceptance

Risk acceptance is the deliberate decision to acknowledge a risk and take no action to reduce it, typically because the cost of mitigation outweighs the benefit or because the risk is unavoidable. In this scenario, the organization recognizes the vulnerability in the legacy system but chooses to continue operating it due to critical business needs, which is a textbook example of risk acceptance. This is a formal risk response strategy where the organization documents the decision and may implement compensating controls, but does not eliminate or transfer the risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk transfer

    Why it's wrong here

    Transfer shifts the financial impact to a third party, typically via insurance or contractual indemnity; here the organisation retains the loss itself. It is tempting because insurance is common for legacy systems, but transfer requires another party to bear the risk, which the stem does not describe.

  • ✗

    Risk avoidance

    Why it's wrong here

    Avoidance eliminates the activity or system generating the risk entirely; the organisation continues running the legacy system because operations depend on it. It is tempting because avoidance sounds like accepting an unpatched system, yet it actually requires decommissioning or replacing the system.

  • ✗

    Risk mitigation

    Why it's wrong here

    Mitigation reduces likelihood or impact through controls such as patching, segmentation or compensating safeguards; the stem explicitly states the system cannot be patched and the risk is tolerated as-is. It is tempting because mitigation is the usual response to vulnerabilities, but no control is applied here.

  • ✓

    Risk acceptance

    Why this is correct

    Accepting the risk means the organisation acknowledges the legacy system's unpatched exposure and consciously chooses to tolerate it because continued operation outweighs the potential loss. No control is applied to reduce it; the residual risk is formally retained.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.