Courseiva
Security and Risk ManagementhardMultiple ChoiceObjective-mapped

CISSP Security and Risk Management Practice Question

A security manager is evaluating risk responses for a high-likelihood, low-impact risk. The cost of mitigation exceeds the potential loss. Which risk response strategy is most appropriate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Accept

When the cost of mitigation exceeds the potential loss, accepting the risk is the most cost-effective response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Avoid

    Why it's wrong here

    Avoiding risk involves completely eliminating the activity, process, or asset that generates the risk. This strategy is typically reserved for situations where the risk's potential impact and likelihood are so severe that no other response is feasible or cost-effective, or where the activity itself is deemed unacceptable. In this scenario, simply eliminating the activity might be an overreaction if the potential loss is low, even with high likelihood, potentially sacrificing business value unnecessarily.

  • Mitigate

    Why it's wrong here

    Mitigation involves implementing controls or countermeasures to reduce either the likelihood of a risk event occurring or its potential impact. However, this option is inappropriate here because the cost of implementing such mitigation controls demonstrably exceeds the potential financial loss that would result if the risk event materializes. Pursuing mitigation when its cost outweighs the potential loss is not a fiscally responsible or effective risk management strategy, as it results in a net negative economic outcome for the organization.

  • Transfer

    Why it's wrong here

    Transferring this risk to a third party, such as through insurance, is inappropriate because the cost of mitigation already exceeds the potential loss, meaning the premium or contractual cost of transfer would likely also exceed the loss, making it economically inefficient. This option is tempting because transfer is typically correct for high-impact, low-likelihood risks where the cost of a rare catastrophic event is shifted to an insurer. Here, the risk is high-likelihood and low-impact, so acceptance is the correct strategy, as the loss is cheaper to absorb than any paid response.

  • Accept

    Why this is correct

    Accepting the risk means consciously deciding to take no action to reduce the likelihood or impact of a risk, and instead bearing the potential consequences if the risk materializes. This strategy is economically sound and appropriate when the cost of implementing any other risk response, such as mitigation or transfer, is greater than the potential financial loss that would be incurred if the risk event occurs. For high-likelihood, low-impact risks where response costs exceed potential losses, acceptance is the most pragmatic and cost-effective approach.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.