SSCP Risk Identification, Monitoring, and Analysis Practice Question
A security analyst at a financial firm is reviewing the risk register and notes that the firm has purchased a cyber insurance policy to cover losses from a data breach. In risk management terms, which of the following best describes this action?
⚠ Common exam trap
The trap here is assuming that buying insurance reduces the likelihood or impact of a breach rather than simply transferring the financial loss.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk transference
Risk transference is the correct classification because cyber insurance shifts the financial consequences of a data breach to an external insurer. The organization still owns the risk operationally, but the monetary impact is contractually borne by another party. This is a standard risk treatment option alongside avoidance, mitigation, and acceptance, and it is commonly used for low-frequency, high-impact events such as major data breaches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Risk transference
Why this is correct
Risk transference shifts the financial impact of a risk to a third party, typically through insurance or contractual agreements. By purchasing cyber insurance, the firm transfers the monetary loss from a breach to the insurer while still retaining the operational and reputational risk. This matches the scenario precisely, as the firm is not reducing the likelihood but is offsetting the financial burden.
- ✗
Risk mitigation
Why it's wrong here
Risk mitigation reduces the probability or impact of a risk through controls such as firewalls, encryption, or security awareness training. Insurance does not reduce the chance of a breach or its operational impact; it only compensates for financial loss after the fact. Therefore, calling this mitigation mischaracterizes the action, as no control is applied to the threat itself.
- ✗
Risk avoidance
Why it's wrong here
Risk avoidance means eliminating the activity that generates the risk altogether, such as discontinuing online banking or refusing to store customer data. Purchasing insurance does not remove the underlying threat or the activity; it only shifts the financial consequence. Because the firm continues to operate and retain breach exposure, this is not avoidance, making this choice incorrect for the scenario.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance means acknowledging the risk and choosing to bear the potential loss without taking further action. The firm here is taking deliberate action by purchasing a policy, so it is not passively accepting the risk. Acceptance would involve documenting the risk and setting aside no additional resources, which contradicts the scenario of acquiring insurance coverage.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.