mediumMultiple Select
CCSP Practice Question: Which THREE of the following are common risk…
Which THREE of the following are common risk treatment options in cloud risk management?
⚠ Common exam trap
Avoidance is a valid risk treatment and should not be dismissed; acceptance is also not the same as ignoring risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transference
In cloud risk management, risk treatment follows the standard ISO 27005 / NIST RMF model, and the three marked options are core treatment strategies. B (Transference) is correct because risk can be shifted to another party, typically via cyber-insurance or by contractual allocation of liability to a cloud provider under a shared responsibility model. C (Avoidance) is correct because an organization can eliminate a risk by not performing the activity that creates it, such as choosing not to deploy a workload in the cloud or not using a specific service. E (Acceptance) is correct because a risk may be knowingly retained when its likelihood or impact is within the organization's risk appetite, documented in a risk register with management sign-off. A (Ignorance) is not a valid treatment because failing to identify or acknowledge a risk does not mitigate it and violates governance requirements. D (Deletion) is not a risk treatment option; deleting data or resources is a technical action that may support avoidance or mitigation, but it is not one of the recognized treatment categories.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ignorance
Why it's wrong here
Ignorance is not a risk treatment; unrecognised risk cannot be managed, and the standard options are avoid, transfer, mitigate and accept. It is tempting because acceptance resembles doing nothing, and would be correct if the stem asked about knowingly retaining a risk within tolerance.
- ✓
Transference
Why this is correct
Transference shifts risk to a third party, typically via insurance or contractual clauses. In cloud risk management, the customer transfers residual liability to the provider through the service agreement, making this a recognised treatment option alongside mitigation, avoidance and acceptance.
- ✓
Avoidance
Why this is correct
Avoidance eliminates the risk entirely by not undertaking the activity that creates it, such as declining to store regulated data in a particular cloud deployment. This removes exposure rather than reducing or shifting it, making it a standard risk treatment option.
- ✗
Deletion
Why it's wrong here
Deletion is not a recognised risk treatment; destroying data or assets removes the risk source but is classified under risk avoidance, not as a separate treatment option. It is tempting because deletion genuinely eliminates exposure, and would be correct if the question asked for a way to avoid a risk entirely.
- ✓
Acceptance
Why this is correct
Acceptance involves acknowledging a risk and retaining it without further action, typically when the cost of treatment exceeds the potential impact. It is a legitimate treatment option provided the organisation documents the decision and the risk remains within its stated tolerance.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.