Courseiva
Security Principles →hardMultiple Select

ISC2 CC Security Principles Practice Question

Which THREE of the following are examples of risk mitigation? (Select THREE)

⚠ Common exam trap

CC often tests the distinction between risk mitigation and other risk responses like acceptance or transference; candidates must remember that insurance is transference, not mitigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing access controls to limit user permissions

Option A is correct because implementing access controls (e.g., role-based access control following least privilege) directly reduces the likelihood and impact of unauthorized actions, which is the essence of risk mitigation. Option C is correct because encrypting sensitive data at rest (e.g., AES-256) reduces the impact of a data breach by rendering stolen data unreadable, thereby lowering overall risk. Option D is correct because installing antivirus/anti-malware on all endpoints provides detective and preventive controls that reduce the likelihood of malware infections and their spread. Option B is not mitigation but risk acceptance, since the organization consciously chooses to tolerate the vulnerability without applying controls. Option E is risk transference (sharing risk with an insurer via a financial mechanism), not mitigation, because it does not reduce the likelihood or impact of the risk itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implementing access controls to limit user permissions

    Why this is correct

    Implementing access controls directly reduces the likelihood of unauthorised actions by enforcing least privilege, satisfying the stem's requirement for risk mitigation. Rather than transferring or accepting risk, it lowers inherent exposure through preventive technical controls such as role-based access assignments in Microsoft Entra ID.

  • ✗

    Deciding not to fix a low-risk vulnerability due to cost

    Why it's wrong here

    Accepting a low-risk vulnerability is risk acceptance, not mitigation — no control is applied to reduce likelihood or impact. It tempts because cost-benefit analysis legitimately justifies accepting trivial risks, and formal acceptance with documented sign-off is the correct choice when remediation cost exceeds potential loss.

  • ✓

    Encrypting sensitive data at rest

    Why this is correct

    Encrypting data at rest directly reduces the likelihood and impact of unauthorised disclosure, satisfying the stem's requirement for risk mitigation. It is a preventive control that lowers residual risk by rendering stolen files unreadable without keys, unlike risk acceptance, avoidance or transference, which handle threats without reducing exposure.

  • ✓

    Installing antivirus software on all endpoints

    Why this is correct

    Installing antivirus software on all endpoints mitigates risk by reducing the likelihood that malware executes successfully, directly satisfying the stem's requirement for a risk mitigation example. It lowers the probability component of risk rather than transferring or avoiding it, making it a preventive control that decreases residual risk across the endpoint estate.

  • ✗

    Purchasing cyber insurance

    Why it's wrong here

    Cyber insurance transfers residual financial loss after an incident; it reduces no likelihood or impact of the event itself, so it is not mitigation. It tempts because it is a recognised risk-treatment option, and would be the answer if the question asked about risk transference.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.