Courseiva
Security and Risk ManagementmediumMultiple SelectObjective-mapped

CISSP Security and Risk Management Practice Question

Which THREE of the following are valid risk response strategies?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Transfer

Common risk responses include Avoid, Transfer, Mitigate, and Accept.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Transfer

    Why this is correct

    Risk transfer is a strategic approach where the financial liability or responsibility for a specific risk is contractually shifted to a third party. This does not eliminate the underlying risk event itself, but rather reallocates the potential financial impact or operational burden. Common methods include purchasing insurance policies, outsourcing functions to vendors who assume associated risks, or incorporating indemnification clauses into service level agreements, thereby protecting the organization from direct financial loss.

  • Eliminate

    Why it's wrong here

    While intuitively appealing, "eliminate" is not a formally recognized or standard risk response strategy within established cybersecurity and risk management frameworks like ISO 31000 or NIST SP 800-30. The concept it attempts to convey is more precisely and accurately captured by the "avoid" strategy, which specifically entails ceasing the activity that gives rise to the risk. Using "eliminate" can lead to ambiguity and confusion with other, more defined risk treatment options.

  • Avoid

    Why this is correct

    Risk avoidance is a proactive strategy where an organization makes a deliberate decision not to engage in or continue an activity that inherently carries an unacceptable level of risk. By completely ceasing the risk-generating activity, the organization ensures that the specific risk event can no longer occur, effectively removing the risk entirely. Examples include declining to launch a product with critical security flaws or opting out of a market segment due to extreme regulatory uncertainty.

  • Mitigate

    Why this is correct

    Risk mitigation involves implementing controls, safeguards, or countermeasures designed to reduce either the probability of a risk event occurring or the severity of its potential impact if it does materialize. This strategy aims to bring the risk down to an acceptable level without necessarily discontinuing the associated activity. Examples include deploying firewalls to reduce cyberattack likelihood, encrypting data to lessen the impact of a breach, or implementing robust backup and recovery plans.

  • Ignore

    Why it's wrong here

    "Ignore" is not considered a legitimate, professional, or defensible risk response strategy within any recognized cybersecurity or business risk management framework. While an organization might inadvertently or implicitly ignore a risk due to oversight or lack of resources, this is a failure of governance, not a deliberate strategy. A legitimate response, even for risks deemed low priority, would be "accept," which involves a conscious, informed decision to tolerate the risk and its potential consequences.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.