Courseiva
Security Principles →easyMultiple Choice

ISC2 CC Security Principles Practice Question

Which risk management strategy involves implementing security controls to reduce the likelihood or impact of a risk?

⚠ Common exam trap

Test-takers frequently confuse mitigation with avoidance or acceptance; candidates often pick 'avoidance' when the question mentions reducing likelihood, but avoidance means eliminating the activity altogether.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk mitigation

Risk mitigation involves implementing security controls to reduce either the likelihood or the impact of a risk. This is the most common risk management strategy because it addresses the risk directly rather than shifting or avoiding it. Examples include patching vulnerabilities, deploying firewalls, or enforcing MFA to lower the probability of exploitation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk acceptance

    Why it's wrong here

    Risk acceptance documents a decision to tolerate the risk without adding controls, so likelihood and impact remain as they are. It is tempting because it requires no budget or engineering effort, yet acceptance suits risks below tolerance thresholds or where control cost exceeds the potential loss.

  • ✓

    Risk mitigation

    Why this is correct

    Risk mitigation applies controls that lower either the likelihood or the impact of a threat exploiting a vulnerability. It differs from avoidance, transference and acceptance, which respectively eliminate the activity, shift the loss, or retain the exposure.

  • ✗

    Risk avoidance

    Why it's wrong here

    Risk avoidance eliminates the activity or asset generating the risk altogether, so no control reduces likelihood or impact because the exposure ceases to exist. It is tempting as the safest-sounding strategy, yet avoidance suits risks whose residual exposure cannot be managed economically.

  • ✗

    Risk transfer

    Why it's wrong here

    Risk transfer shifts financial consequence to a third party, typically via insurance or contractual indemnity, leaving likelihood and impact unchanged. It is tempting because insurance feels protective, yet transfer suits low-frequency, high-severity risks where the organisation prefers paying premiums over funding controls.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.