Courseiva
hardMultiple Choice

CISSP Practice Question: During a risk assessment, a critical asset has a…

During a risk assessment, a critical asset has a vulnerability with a CVSS score of 9.0. Which risk treatment strategy is most appropriate if the cost to mitigate exceeds the asset's value?

⚠ Common exam trap

Candidates often assume that a high-severity vulnerability (such as CVSS 9.0) must always be mitigated or transferred. However, CISSP questions test your business acumen: if the cost of the countermeasure exceeds the asset's value, the correct business decision is to accept the risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Acceptance

In risk management, a fundamental rule is that the cost of a safeguard (mitigation) should never exceed the value of the asset being protected. If mitigating a vulnerability costs more than the asset is worth, the organization should choose to accept the risk (Risk Acceptance). Spending more to protect an asset than the asset itself is worth is financially illogical.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Transfer

    Why it's wrong here

    When faced with a critical asset's vulnerability where direct mitigation is cost-prohibitive or avoidance is impractical, transferring the risk's financial impact is a prudent strategy. This typically involves purchasing cyber insurance, which shifts the financial burden of potential losses from a security incident to a third-party insurer. While the vulnerability itself remains, the organization's financial exposure is significantly reduced, making it a viable and often cost-effective solution for managing residual risk.

  • ✓

    Acceptance

    Why this is correct

    Accepting a significant vulnerability on a critical asset without implementing any treatment is generally an irresponsible risk management decision. This approach implies that the potential impact of a breach or compromise on the critical asset is deemed tolerable, which is rarely the case for assets vital to business continuity or regulatory compliance. Such a strategy is typically reserved for low-impact, low-probability risks, not for critical infrastructure.

  • ✗

    Avoidance

    Why it's wrong here

    Risk avoidance for a critical asset would necessitate eliminating the asset or the activity that introduces the vulnerability entirely. Given the asset's critical nature, discontinuing its use would likely lead to severe operational disruptions, significant revenue loss, or an inability to meet core business objectives. Therefore, while it eliminates the risk, avoidance is often an impractical and unacceptable solution for essential organizational components.

  • ✗

    Mitigation

    Why it's wrong here

    Mitigation involves implementing controls to reduce the likelihood or impact of a vulnerability, such as patching, reconfiguring systems, or deploying new security technologies. However, if the financial investment required for effective mitigation measures exceeds the critical asset's value or the potential cost of a compromise, it becomes economically unsound. Investing more in protection than the asset is worth violates fundamental risk management principles, making it an unwise choice in this specific scenario.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.