mediumMultiple ChoiceObjective-mapped
CISSP Practice Question: A business is evaluating risk treatment options…
A business is evaluating risk treatment options for a high-likelihood, low-impact risk. The cost of mitigation exceeds the potential loss. Which risk treatment strategy is most appropriate?
⚠ Common exam trap
Test-takers frequently assume insurance (transfer) is always the best option for any risk, but the CISSP exam emphasizes cost-benefit analysis, making acceptance the correct choice when mitigation costs exceed the potential loss.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk acceptance with documented decision
When the cost of mitigation exceeds the potential loss, risk acceptance is the most cost-effective strategy. The business formally acknowledges the risk and documents the decision to accept it, often because the residual risk is within the organization's risk appetite. This aligns with the principle that not all risks must be mitigated or transferred if the economic justification is absent.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk transfer by purchasing insurance
Why it's wrong here
While insurance can transfer financial risk, it is not always the most economical solution for every risk profile. If the cost of premiums for a high-likelihood, low-impact risk significantly outweighs the potential financial loss, then transferring the risk becomes an inefficient use of resources. The organization would be paying more to protect against a loss than the loss itself, making it an unsuitable treatment option from a cost-benefit perspective.
- ✓
Risk acceptance with documented decision
Why this is correct
Risk acceptance is the appropriate strategy when the cost of implementing other risk treatment options, such as mitigation or transfer, exceeds the potential impact of the risk itself. For a high-likelihood, low-impact risk, the financial outlay for controls or insurance might be greater than the actual loss incurred if the risk materializes. A formal, documented decision ensures that management acknowledges the risk, understands its implications, and accepts the potential consequences, providing accountability and a basis for future review.
- ✗
Risk mitigation by implementing additional controls
Why it's wrong here
Implementing additional controls to mitigate a high-likelihood, low-impact risk is often not a cost-effective strategy. If the expense associated with designing, deploying, and maintaining new security controls surpasses the potential financial or operational loss that the risk could cause, then mitigation is economically unsound. The goal of risk management is to reduce risk to an acceptable level efficiently, not to eliminate all risk at any cost.
- ✗
Risk avoidance by discontinuing the activity
Why it's wrong here
Risk avoidance, which involves ceasing the activity that generates the risk, is generally considered an extreme measure. For a high-likelihood, low-impact risk, completely discontinuing the associated business function or process would likely result in a disproportionate loss of business value or operational capability compared to the actual risk exposure. This approach is typically reserved for risks with catastrophic potential where no other treatment is feasible or acceptable.
Go deeper
Related to this question
Learn chapter
Incident Response and Business Continuity
Key term
Risk appetite
Risk appetite is the amount of risk an organization is willing to accept in pursuit of its objectives, defining the boundaries for decision-making.
Key term
Residual risk
Residual risk is the level of risk that remains after all security controls and countermeasures have been applied.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.