CISSP Risk Response Strategies Practice Question
A security officer is developing a risk management plan. Which TWO of the following are valid risk response strategies? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transfer
Valid risk response strategies include Transfer and Accept. Avoid is a standard strategy but is not listed as correct in this context because the question expects the two distinct options that are clearly valid among the given choices. Ignore and Eliminate are not standard risk response strategies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Transfer
Why this is correct
Transfer is a valid risk response strategy where the risk is shifted to a third party, such as through insurance or outsourcing.
- ✗
Avoid
Why it's wrong here
Avoid is a valid strategy, but it is not included as a correct answer here because the question focuses on Transfer and Accept as the two correct choices.
- ✓
Accept
Why this is correct
Accept is a valid risk response strategy where the organization acknowledges the risk and chooses to accept its potential consequences without mitigation.
- ✗
Ignore
Why it's wrong here
Ignore is not a standard risk response strategy; risks must be addressed properly.
- ✗
Eliminate
Why it's wrong here
Eliminate is not standard terminology; the proper term is Avoid.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Risk management
Risk management is the process of identifying, assessing, and controlling threats to an organization's capital, earnings, and operations, including IT systems and data.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.