CISSP Security and Risk Management Practice Question
A company decides to purchase cyber insurance to cover potential losses from data breaches. Which risk response strategy does this represent?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transfer
Transfer involves shifting the risk to a third party, such as through insurance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Transfer
Why this is correct
Purchasing cyber insurance is a classic example of risk transfer. This strategy involves shifting the financial responsibility for potential losses, such as those arising from data breaches, ransomware attacks, or business interruption, to a third party—the insurance provider. While the underlying operational risk itself still exists, the financial impact on the company is significantly reduced, as the insurer assumes the cost of recovery, legal fees, and other covered damages. This allows the organization to mitigate the severe financial consequences of a cyber incident without eliminating the threat entirely.
- ✗
Accept
Why it's wrong here
Risk acceptance occurs when an organization acknowledges a specific risk but decides not to implement any controls or countermeasures to reduce its likelihood or impact, often due to low perceived severity, high cost of mitigation, or a strategic business decision. In this scenario, the company would bear the full financial burden of any cyber incident itself. Purchasing cyber insurance directly contradicts this strategy, as it explicitly takes action to offload the financial consequences rather than accepting them.
- ✗
Avoid
Why it's wrong here
Risk avoidance involves eliminating the activity or asset that gives rise to the risk altogether, thereby completely removing the possibility of the risk occurring. For instance, if a company avoids storing sensitive customer data, it avoids the risk of a data breach related to that data. Purchasing cyber insurance, however, does not eliminate the underlying cyber threats or the company's engagement in digital activities that create those risks; instead, it provides a financial safety net for incidents that might still occur.
- ✗
Mitigate
Why it's wrong here
Risk mitigation focuses on implementing controls and safeguards to reduce either the likelihood of a risk event occurring or the severity of its impact if it does occur. Examples include deploying firewalls, implementing strong access controls, or conducting employee security awareness training. While these actions directly reduce the threat landscape, purchasing cyber insurance does not inherently reduce the probability of a cyberattack or the immediate operational disruption; rather, it addresses the financial aftermath by providing funds for recovery and damages.
Go deeper
Related to this question
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.