CISSP Security and Risk Management Practice Question
Which THREE of the following are valid risk response strategies?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transfer
Common risk responses include Avoid, Transfer, Mitigate, and Accept.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Transfer
Why this is correct
Risk transfer is a strategic approach where the financial liability or responsibility for a specific risk is contractually shifted to a third party. This does not eliminate the underlying risk event itself, but rather reallocates the potential financial impact or operational burden. Common methods include purchasing insurance policies, outsourcing functions to vendors who assume associated risks, or incorporating indemnification clauses into service level agreements, thereby protecting the organization from direct financial loss.
- ✗
Eliminate
Why it's wrong here
While intuitively appealing, "eliminate" is not a formally recognized or standard risk response strategy within established cybersecurity and risk management frameworks like ISO 31000 or NIST SP 800-30. The concept it attempts to convey is more precisely and accurately captured by the "avoid" strategy, which specifically entails ceasing the activity that gives rise to the risk. Using "eliminate" can lead to ambiguity and confusion with other, more defined risk treatment options.
- ✓
Avoid
Why this is correct
Risk avoidance is a proactive strategy where an organization makes a deliberate decision not to engage in or continue an activity that inherently carries an unacceptable level of risk. By completely ceasing the risk-generating activity, the organization ensures that the specific risk event can no longer occur, effectively removing the risk entirely. Examples include declining to launch a product with critical security flaws or opting out of a market segment due to extreme regulatory uncertainty.
- ✓
Mitigate
Why this is correct
Risk mitigation involves implementing controls, safeguards, or countermeasures designed to reduce either the probability of a risk event occurring or the severity of its potential impact if it does materialize. This strategy aims to bring the risk down to an acceptable level without necessarily discontinuing the associated activity. Examples include deploying firewalls to reduce cyberattack likelihood, encrypting data to lessen the impact of a breach, or implementing robust backup and recovery plans.
- ✗
Ignore
Why it's wrong here
"Ignore" is not considered a legitimate, professional, or defensible risk response strategy within any recognized cybersecurity or business risk management framework. While an organization might inadvertently or implicitly ignore a risk due to oversight or lack of resources, this is a failure of governance, not a deliberate strategy. A legitimate response, even for risks deemed low priority, would be "accept," which involves a conscious, informed decision to tolerate the risk and its potential consequences.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.