SSCP Risk Identification, Monitoring, and Analysis Practice Question
A healthcare organization has completed a risk assessment and documented a set of identified risks in its risk register. Management decides not to purchase cyber insurance and not to implement any additional safeguards for a specific risk involving legacy medical devices. Which risk response strategy has management chosen?
⚠ Common exam trap
The trap here is reading the absence of action as a failure to respond, when formally documented inaction is itself the acceptance strategy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk acceptance
When management reviews a documented risk and consciously decides to add no controls and buy no insurance, the organization is accepting the risk. Acceptance is recorded in the risk register with a rationale and often a review date, so the decision is deliberate and auditable. Mitigation, transfer, and avoidance all require concrete actions that were explicitly declined for the legacy devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk transfer
Why it's wrong here
Risk transfer shifts financial exposure to a third party, typically through cyber insurance or contractual indemnification. The scenario explicitly states that management declined to purchase cyber insurance, so no transfer has occurred. Without a policy or contract absorbing the loss, this strategy cannot apply to the legacy medical device risk.
- ✓
Risk acceptance
Why this is correct
Acceptance means management acknowledges the risk, documents the decision, and proceeds without additional controls or insurance. Because the organization chose to add no safeguards and no coverage for the legacy device risk, it has formally accepted the residual exposure. Acceptance is a legitimate strategy when the cost of treatment exceeds the potential loss.
- ✗
Risk avoidance
Why it's wrong here
Avoidance eliminates the risk by discontinuing the activity or removing the asset entirely, such as decommissioning the legacy devices. The organization continues to operate the medical devices, so the risk source remains present. Choosing to live with exposure while keeping the activity is the opposite of avoidance in this scenario.
- ✗
Risk mitigation
Why it's wrong here
Risk mitigation means applying controls to reduce the likelihood or impact of a threat. Management here elected to add no safeguards and no insurance, so nothing is being reduced. Mitigation would require actions such as network segmentation, compensating controls, or device replacement, none of which were selected in this scenario.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.