ISC2 CC Security Principles Practice Question
Which THREE of the following are considered risk management strategies? (Select THREE)
⚠ Common exam trap
CC often tests the confusion between risk process steps (assessment, analysis) and risk response strategies (accept, transfer, mitigate, avoid) — candidates must distinguish 'what you do to understand risk' from 'what you do about risk.'
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk acceptance
Risk acceptance (A) is a valid risk management strategy because the organization consciously decides to tolerate the identified risk without taking action, often when the cost of mitigation exceeds the potential impact. Risk transfer (D) is a strategy that shifts the financial impact of a risk to a third party, typically through insurance or outsourcing contracts. Risk mitigation (E) is a strategy that reduces the probability or impact of a risk by implementing controls, making it a core risk-handling approach. Risk assessment (B) and risk analysis (C) are not strategies themselves; they are earlier processes used to identify, evaluate, and prioritize risks before a response strategy is selected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Risk acceptance
Why this is correct
Risk acceptance is a documented decision to tolerate a risk without applying further controls, typically when the cost of treatment exceeds the potential loss. It is one of the recognised risk management strategies alongside transfer, mitigation and avoidance, satisfying the question's requirement to identify them.
- ✗
Risk assessment
Why it's wrong here
Risk assessment is a process that evaluates and prioritises risks, not a strategy for responding to them. It is tempting because assessment precedes response planning, yet the strategies are avoidance, transfer, mitigation, acceptance and exploitation. Assessment informs strategy selection rather than constituting one.
- ✗
Risk analysis
Why it's wrong here
Risk analysis is a technique performed within risk management, not a strategy for handling identified risks. It is tempting because analysis underpins the process, but the strategies themselves are avoidance, transfer, mitigation, acceptance and exploitation. Analysis produces the information those strategies act upon.
- ✓
Risk transfer
Why this is correct
Risk transfer shifts the financial consequence of a risk to a third party, most commonly through insurance or contractual indemnity. The organisation retains the risk itself but not its financial impact, making transfer one of the recognised risk management strategies the question asks for.
- ✓
Risk mitigation
Why this is correct
Risk mitigation reduces either the likelihood or the impact of a risk by applying controls, such as patching, segmentation or training. It is a recognised risk management strategy alongside acceptance, transfer and avoidance, satisfying the requirement to identify the strategies listed.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Risk assessment
Risk assessment is the process of identifying, analyzing, and evaluating potential threats to an organization's assets to determine the likelihood and impact of those threats, and to decide on appropriate treatment measures.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.