Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

A healthcare organization has completed a risk assessment and documented a set of identified risks in its risk register. Management decides not to purchase cyber insurance and not to implement any additional safeguards for a specific risk involving legacy medical devices. Which risk response strategy has management chosen?

⚠ Common exam trap

The trap here is reading the absence of action as a failure to respond, when formally documented inaction is itself the acceptance strategy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk acceptance

When management reviews a documented risk and consciously decides to add no controls and buy no insurance, the organization is accepting the risk. Acceptance is recorded in the risk register with a rationale and often a review date, so the decision is deliberate and auditable. Mitigation, transfer, and avoidance all require concrete actions that were explicitly declined for the legacy devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk transfer

    Why it's wrong here

    Risk transfer shifts financial exposure to a third party, typically through cyber insurance or contractual indemnification. The scenario explicitly states that management declined to purchase cyber insurance, so no transfer has occurred. Without a policy or contract absorbing the loss, this strategy cannot apply to the legacy medical device risk.

  • ✓

    Risk acceptance

    Why this is correct

    Acceptance means management acknowledges the risk, documents the decision, and proceeds without additional controls or insurance. Because the organization chose to add no safeguards and no coverage for the legacy device risk, it has formally accepted the residual exposure. Acceptance is a legitimate strategy when the cost of treatment exceeds the potential loss.

  • ✗

    Risk avoidance

    Why it's wrong here

    Avoidance eliminates the risk by discontinuing the activity or removing the asset entirely, such as decommissioning the legacy devices. The organization continues to operate the medical devices, so the risk source remains present. Choosing to live with exposure while keeping the activity is the opposite of avoidance in this scenario.

  • ✗

    Risk mitigation

    Why it's wrong here

    Risk mitigation means applying controls to reduce the likelihood or impact of a threat. Management here elected to add no safeguards and no insurance, so nothing is being reduced. Mitigation would require actions such as network segmentation, compensating controls, or device replacement, none of which were selected in this scenario.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.