CISSP Security and Risk Management Practice Question
A security manager is evaluating risk responses for a high-likelihood, low-impact risk. The cost of mitigation exceeds the potential loss. Which risk response strategy is most appropriate?
⚠ Common exam trap
CISSP often tests whether candidates reflexively choose 'mitigate' as the 'safest' answer, ignoring the cost-benefit analysis that makes acceptance the correct business-aligned choice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accept
Risk acceptance is the appropriate response when the cost of mitigating a risk exceeds the potential loss and the risk falls within the organization's risk tolerance. For a high-likelihood, low-impact risk where mitigation is not cost-effective, accepting the risk (with documented awareness and monitoring) is the rational business decision.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Avoid
Why it's wrong here
Avoiding risk involves completely eliminating the activity, process, or asset that generates the risk. This strategy is typically reserved for situations where the risk's potential impact and likelihood are so severe that no other response is feasible or cost-effective, or where the activity itself is deemed unacceptable. In this scenario, simply eliminating the activity might be an overreaction if the potential loss is low, even with high likelihood, potentially sacrificing business value unnecessarily.
- ✗
Mitigate
Why it's wrong here
Mitigation involves implementing controls or countermeasures to reduce either the likelihood of a risk event occurring or its potential impact. However, this option is inappropriate here because the cost of implementing such mitigation controls demonstrably exceeds the potential financial loss that would result if the risk event materializes. Pursuing mitigation when its cost outweighs the potential loss is not a fiscally responsible or effective risk management strategy, as it results in a net negative economic outcome for the organization.
- ✗
Transfer
Why it's wrong here
Transferring this risk to a third party, such as through insurance, is inappropriate because the cost of mitigation already exceeds the potential loss, meaning the premium or contractual cost of transfer would likely also exceed the loss, making it economically inefficient. This option is tempting because transfer is typically correct for high-impact, low-likelihood risks where the cost of a rare catastrophic event is shifted to an insurer. Here, the risk is high-likelihood and low-impact, so acceptance is the correct strategy, as the loss is cheaper to absorb than any paid response.
- ✓
Accept
Why this is correct
Accepting the risk means consciously deciding to take no action to reduce the likelihood or impact of a risk, and instead bearing the potential consequences if the risk materializes. This strategy is economically sound and appropriate when the cost of implementing any other risk response, such as mitigation or transfer, is greater than the potential financial loss that would be incurred if the risk event occurs. For high-likelihood, low-impact risks where response costs exceed potential losses, acceptance is the most pragmatic and cost-effective approach.
Go deeper
Related to this question
Learn chapter
Incident Response and Business Continuity
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Risk tolerance
Risk tolerance is the amount of risk an organization or individual is willing to accept in pursuit of its objectives, defining the boundary between acceptable and unacceptable losses.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.