Courseiva
Security Principles →hardMultiple Select

ISC2 CC Security Principles Practice Question

Which THREE of the following are considered risk management strategies? (Select THREE)

⚠ Common exam trap

CC often tests the confusion between risk process steps (assessment, analysis) and risk response strategies (accept, transfer, mitigate, avoid) — candidates must distinguish 'what you do to understand risk' from 'what you do about risk.'

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk acceptance

Risk acceptance (A) is a valid risk management strategy because the organization consciously decides to tolerate the identified risk without taking action, often when the cost of mitigation exceeds the potential impact. Risk transfer (D) is a strategy that shifts the financial impact of a risk to a third party, typically through insurance or outsourcing contracts. Risk mitigation (E) is a strategy that reduces the probability or impact of a risk by implementing controls, making it a core risk-handling approach. Risk assessment (B) and risk analysis (C) are not strategies themselves; they are earlier processes used to identify, evaluate, and prioritize risks before a response strategy is selected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk acceptance

    Why this is correct

    Risk acceptance is a documented decision to tolerate a risk without applying further controls, typically when the cost of treatment exceeds the potential loss. It is one of the recognised risk management strategies alongside transfer, mitigation and avoidance, satisfying the question's requirement to identify them.

  • ✗

    Risk assessment

    Why it's wrong here

    Risk assessment is a process that evaluates and prioritises risks, not a strategy for responding to them. It is tempting because assessment precedes response planning, yet the strategies are avoidance, transfer, mitigation, acceptance and exploitation. Assessment informs strategy selection rather than constituting one.

  • ✗

    Risk analysis

    Why it's wrong here

    Risk analysis is a technique performed within risk management, not a strategy for handling identified risks. It is tempting because analysis underpins the process, but the strategies themselves are avoidance, transfer, mitigation, acceptance and exploitation. Analysis produces the information those strategies act upon.

  • ✓

    Risk transfer

    Why this is correct

    Risk transfer shifts the financial consequence of a risk to a third party, most commonly through insurance or contractual indemnity. The organisation retains the risk itself but not its financial impact, making transfer one of the recognised risk management strategies the question asks for.

  • ✓

    Risk mitigation

    Why this is correct

    Risk mitigation reduces either the likelihood or the impact of a risk by applying controls, such as patching, segmentation or training. It is a recognised risk management strategy alongside acceptance, transfer and avoidance, satisfying the requirement to identify the strategies listed.

Go deeper

Related to this question

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.