CISSP Security and Risk Management Practice Question
A security manager is evaluating risk responses for a high-likelihood, low-impact risk. The cost of mitigation exceeds the potential loss. Which risk response strategy is most appropriate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accept
When the cost of mitigation exceeds the potential loss, accepting the risk is the most cost-effective response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Avoid
Why it's wrong here
Avoiding risk involves completely eliminating the activity, process, or asset that generates the risk. This strategy is typically reserved for situations where the risk's potential impact and likelihood are so severe that no other response is feasible or cost-effective, or where the activity itself is deemed unacceptable. In this scenario, simply eliminating the activity might be an overreaction if the potential loss is low, even with high likelihood, potentially sacrificing business value unnecessarily.
- ✗
Mitigate
Why it's wrong here
Mitigation involves implementing controls or countermeasures to reduce either the likelihood of a risk event occurring or its potential impact. However, this option is inappropriate here because the cost of implementing such mitigation controls demonstrably exceeds the potential financial loss that would result if the risk event materializes. Pursuing mitigation when its cost outweighs the potential loss is not a fiscally responsible or effective risk management strategy, as it results in a net negative economic outcome for the organization.
- ✗
Transfer
Why it's wrong here
Transferring this risk to a third party, such as through insurance, is inappropriate because the cost of mitigation already exceeds the potential loss, meaning the premium or contractual cost of transfer would likely also exceed the loss, making it economically inefficient. This option is tempting because transfer is typically correct for high-impact, low-likelihood risks where the cost of a rare catastrophic event is shifted to an insurer. Here, the risk is high-likelihood and low-impact, so acceptance is the correct strategy, as the loss is cheaper to absorb than any paid response.
- ✓
Accept
Why this is correct
Accepting the risk means consciously deciding to take no action to reduce the likelihood or impact of a risk, and instead bearing the potential consequences if the risk materializes. This strategy is economically sound and appropriate when the cost of implementing any other risk response, such as mitigation or transfer, is greater than the potential financial loss that would be incurred if the risk event occurs. For high-likelihood, low-impact risks where response costs exceed potential losses, acceptance is the most pragmatic and cost-effective approach.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.