ISC2 CC Security Principles Practice Question
Which risk management strategy involves implementing security controls to reduce the likelihood or impact of a risk?
⚠ Common exam trap
Test-takers frequently confuse mitigation with avoidance or acceptance; candidates often pick 'avoidance' when the question mentions reducing likelihood, but avoidance means eliminating the activity altogether.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk mitigation
Risk mitigation involves implementing security controls to reduce either the likelihood or the impact of a risk. This is the most common risk management strategy because it addresses the risk directly rather than shifting or avoiding it. Examples include patching vulnerabilities, deploying firewalls, or enforcing MFA to lower the probability of exploitation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance documents a decision to tolerate the risk without adding controls, so likelihood and impact remain as they are. It is tempting because it requires no budget or engineering effort, yet acceptance suits risks below tolerance thresholds or where control cost exceeds the potential loss.
- ✓
Risk mitigation
Why this is correct
Risk mitigation applies controls that lower either the likelihood or the impact of a threat exploiting a vulnerability. It differs from avoidance, transference and acceptance, which respectively eliminate the activity, shift the loss, or retain the exposure.
- ✗
Risk avoidance
Why it's wrong here
Risk avoidance eliminates the activity or asset generating the risk altogether, so no control reduces likelihood or impact because the exposure ceases to exist. It is tempting as the safest-sounding strategy, yet avoidance suits risks whose residual exposure cannot be managed economically.
- ✗
Risk transfer
Why it's wrong here
Risk transfer shifts financial consequence to a third party, typically via insurance or contractual indemnity, leaving likelihood and impact unchanged. It is tempting because insurance feels protective, yet transfer suits low-frequency, high-severity risks where the organisation prefers paying premiums over funding controls.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.