Courseiva

CISSP Security and Risk Management Practice Question

A security manager is conducting a risk assessment and needs to categorize the following risk responses: risk avoidance, risk transfer, risk mitigation, and risk acceptance. Which TWO of the following actions are examples of risk transfer? (Choose two.)

⚠ Common exam trap

Candidates often confuse risk transfer with risk mitigation, assuming that any action that reduces risk (like a firewall) is transfer, when transfer specifically involves shifting the risk to a third party.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Outsourcing a critical business function to a third-party provider with a service-level agreement (SLA).

The correct answers are purchasing cyber insurance and outsourcing a critical function with an SLA. Both actions shift the financial or operational impact of a risk to another party. Insurance transfers financial risk, while outsourcing transfers operational risk through contractual agreements, making them valid examples of risk transfer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Outsourcing a critical business function to a third-party provider with a service-level agreement (SLA).

    Why this is correct

    Outsourcing transfers the operational risk to the third-party provider, who is contractually obligated to meet performance and security requirements. The organization retains some residual risk, but the primary responsibility shifts, which is a form of risk transfer. Thus, this action is correct.

  • ✗

    Accepting the risk of a minor vulnerability because the cost of fixing it exceeds the potential loss.

    Why it's wrong here

    Accepting a risk means the organization acknowledges the risk and decides to bear the potential consequences without taking action to transfer or mitigate it. This is risk acceptance, not transfer. The risk remains with the organization, so it is incorrect.

  • ✗

    Implementing a firewall to block unauthorized access to the network.

    Why it's wrong here

    Implementing a firewall is a risk mitigation control that reduces the likelihood of unauthorized access. It does not transfer the risk to another party; instead, it addresses the risk directly by implementing a safeguard. Therefore, it is an example of risk mitigation, not transfer.

  • ✗

    Deciding not to deploy a new application because it introduces unacceptable vulnerabilities.

    Why it's wrong here

    Deciding not to deploy an application eliminates the risk entirely by avoiding the activity. This is risk avoidance, not transfer. The organization chooses to not engage in the risky activity, so no risk is transferred to another party.

  • ✓

    Purchasing cyber insurance to cover potential financial losses from a data breach.

    Why this is correct

    Purchasing cyber insurance transfers the financial impact of a risk to the insurance company. The organization pays a premium and shifts the potential loss, which is a classic example of risk transfer. This action does not reduce the likelihood or impact directly but compensates for losses, making it correct.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.