Courseiva
hardMultiple Select

ISC2 CC Practice Question: Which THREE of the following are acceptable risk…

Which THREE of the following are acceptable risk treatment options according to NIST risk management framework?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk mitigation

Risk avoidance, mitigation, transfer, and acceptance are standard. Risk identification is a step, not treatment. Risk duplication is not a term.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk mitigation

    Why this is correct

    Mitigation reduces risk by applying controls that lower likelihood or impact, and it is one of the NIST SP 800-30 treatment options alongside transfer, avoid and accept. It satisfies the stem's requirement for an acceptable treatment response.

  • ✗

    Risk duplication

    Why it's wrong here

    NIST SP 800-30 defines risk treatment as accept, avoid, mitigate (reduce) and transfer (share); duplication is not among them, since copying a risk does not alter its likelihood or impact. It is tempting because duplicating controls or systems sounds protective, but redundancy is a mitigation technique, not a treatment category.

  • ✓

    Risk transfer

    Why this is correct

    Risk transfer shifts financial liability for a specific threat to a third party, such as an insurer, satisfying the NIST risk management framework’s requirement that an organisation must formally document a risk response decision for each identified risk. This mechanism does not reduce the likelihood or impact of the threat itself, but it meets the framework’s constraint that all risks must be assigned a treatment option.

  • ✗

    Risk identification

    Why it's wrong here

    Identification is the first step of the risk management process, occurring before treatment; NIST SP 800-30 treatment options are accept, avoid, mitigate and transfer. It is tempting because identification is a genuine risk management activity, but it produces the risk register rather than selecting a response to an assessed risk.

  • ✓

    Risk acceptance

    Why this is correct

    Acceptance means knowingly retaining residual risk when treatment costs exceed benefit, and NIST SP 800-30 lists it among the four treatment options with transfer, avoid and mitigate. It directly satisfies the stem's requirement for an acceptable treatment response.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.