CISSP Security and Risk Management Practice Question
A security manager is conducting a risk assessment and needs to categorize the following risk responses: risk avoidance, risk transfer, risk mitigation, and risk acceptance. Which TWO of the following actions are examples of risk transfer? (Choose two.)
⚠ Common exam trap
Candidates often confuse risk transfer with risk mitigation, assuming that any action that reduces risk (like a firewall) is transfer, when transfer specifically involves shifting the risk to a third party.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Outsourcing a critical business function to a third-party provider with a service-level agreement (SLA).
The correct answers are purchasing cyber insurance and outsourcing a critical function with an SLA. Both actions shift the financial or operational impact of a risk to another party. Insurance transfers financial risk, while outsourcing transfers operational risk through contractual agreements, making them valid examples of risk transfer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Outsourcing a critical business function to a third-party provider with a service-level agreement (SLA).
Why this is correct
Outsourcing transfers the operational risk to the third-party provider, who is contractually obligated to meet performance and security requirements. The organization retains some residual risk, but the primary responsibility shifts, which is a form of risk transfer. Thus, this action is correct.
- ✗
Accepting the risk of a minor vulnerability because the cost of fixing it exceeds the potential loss.
Why it's wrong here
Accepting a risk means the organization acknowledges the risk and decides to bear the potential consequences without taking action to transfer or mitigate it. This is risk acceptance, not transfer. The risk remains with the organization, so it is incorrect.
- ✗
Implementing a firewall to block unauthorized access to the network.
Why it's wrong here
Implementing a firewall is a risk mitigation control that reduces the likelihood of unauthorized access. It does not transfer the risk to another party; instead, it addresses the risk directly by implementing a safeguard. Therefore, it is an example of risk mitigation, not transfer.
- ✗
Deciding not to deploy a new application because it introduces unacceptable vulnerabilities.
Why it's wrong here
Deciding not to deploy an application eliminates the risk entirely by avoiding the activity. This is risk avoidance, not transfer. The organization chooses to not engage in the risky activity, so no risk is transferred to another party.
- ✓
Purchasing cyber insurance to cover potential financial losses from a data breach.
Why this is correct
Purchasing cyber insurance transfers the financial impact of a risk to the insurance company. The organization pays a premium and shifts the potential loss, which is a classic example of risk transfer. This action does not reduce the likelihood or impact directly but compensates for losses, making it correct.
Go deeper
Related to this question
Learn chapter
Security Assessment and Testing
Key term
Risk mitigation
Risk mitigation is the process of reducing the likelihood or impact of a potential security threat to an acceptable level through specific controls and actions.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.