ISC2 CC Security Principles Practice Question
Which THREE of the following are examples of risk mitigation? (Select THREE)
⚠ Common exam trap
CC often tests the distinction between risk mitigation and other risk responses like acceptance or transference; candidates must remember that insurance is transference, not mitigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementing access controls to limit user permissions
Option A is correct because implementing access controls (e.g., role-based access control following least privilege) directly reduces the likelihood and impact of unauthorized actions, which is the essence of risk mitigation. Option C is correct because encrypting sensitive data at rest (e.g., AES-256) reduces the impact of a data breach by rendering stolen data unreadable, thereby lowering overall risk. Option D is correct because installing antivirus/anti-malware on all endpoints provides detective and preventive controls that reduce the likelihood of malware infections and their spread. Option B is not mitigation but risk acceptance, since the organization consciously chooses to tolerate the vulnerability without applying controls. Option E is risk transference (sharing risk with an insurer via a financial mechanism), not mitigation, because it does not reduce the likelihood or impact of the risk itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implementing access controls to limit user permissions
Why this is correct
Implementing access controls directly reduces the likelihood of unauthorised actions by enforcing least privilege, satisfying the stem's requirement for risk mitigation. Rather than transferring or accepting risk, it lowers inherent exposure through preventive technical controls such as role-based access assignments in Microsoft Entra ID.
- ✗
Deciding not to fix a low-risk vulnerability due to cost
Why it's wrong here
Accepting a low-risk vulnerability is risk acceptance, not mitigation — no control is applied to reduce likelihood or impact. It tempts because cost-benefit analysis legitimately justifies accepting trivial risks, and formal acceptance with documented sign-off is the correct choice when remediation cost exceeds potential loss.
- ✓
Encrypting sensitive data at rest
Why this is correct
Encrypting data at rest directly reduces the likelihood and impact of unauthorised disclosure, satisfying the stem's requirement for risk mitigation. It is a preventive control that lowers residual risk by rendering stolen files unreadable without keys, unlike risk acceptance, avoidance or transference, which handle threats without reducing exposure.
- ✓
Installing antivirus software on all endpoints
Why this is correct
Installing antivirus software on all endpoints mitigates risk by reducing the likelihood that malware executes successfully, directly satisfying the stem's requirement for a risk mitigation example. It lowers the probability component of risk rather than transferring or avoiding it, making it a preventive control that decreases residual risk across the endpoint estate.
- ✗
Purchasing cyber insurance
Why it's wrong here
Cyber insurance transfers residual financial loss after an incident; it reduces no likelihood or impact of the event itself, so it is not mitigation. It tempts because it is a recognised risk-treatment option, and would be the answer if the question asked about risk transference.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.