Courseiva
Security and Risk ManagementmediumMultiple ChoiceObjective-mapped

CISSP Security and Risk Management Practice Question

A company decides to purchase cyber insurance to cover potential losses from data breaches. Which risk response strategy does this represent?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Transfer

Transfer involves shifting the risk to a third party, such as through insurance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Transfer

    Why this is correct

    Purchasing cyber insurance is a classic example of risk transfer. This strategy involves shifting the financial responsibility for potential losses, such as those arising from data breaches, ransomware attacks, or business interruption, to a third party—the insurance provider. While the underlying operational risk itself still exists, the financial impact on the company is significantly reduced, as the insurer assumes the cost of recovery, legal fees, and other covered damages. This allows the organization to mitigate the severe financial consequences of a cyber incident without eliminating the threat entirely.

  • Accept

    Why it's wrong here

    Risk acceptance occurs when an organization acknowledges a specific risk but decides not to implement any controls or countermeasures to reduce its likelihood or impact, often due to low perceived severity, high cost of mitigation, or a strategic business decision. In this scenario, the company would bear the full financial burden of any cyber incident itself. Purchasing cyber insurance directly contradicts this strategy, as it explicitly takes action to offload the financial consequences rather than accepting them.

  • Avoid

    Why it's wrong here

    Risk avoidance involves eliminating the activity or asset that gives rise to the risk altogether, thereby completely removing the possibility of the risk occurring. For instance, if a company avoids storing sensitive customer data, it avoids the risk of a data breach related to that data. Purchasing cyber insurance, however, does not eliminate the underlying cyber threats or the company's engagement in digital activities that create those risks; instead, it provides a financial safety net for incidents that might still occur.

  • Mitigate

    Why it's wrong here

    Risk mitigation focuses on implementing controls and safeguards to reduce either the likelihood of a risk event occurring or the severity of its impact if it does occur. Examples include deploying firewalls, implementing strong access controls, or conducting employee security awareness training. While these actions directly reduce the threat landscape, purchasing cyber insurance does not inherently reduce the probability of a cyberattack or the immediate operational disruption; rather, it addresses the financial aftermath by providing funds for recovery and damages.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.