Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

A security team identifies a vulnerability in a web application that allows SQL injection. Which risk response strategy involves implementing input validation and parameterized queries to reduce the risk to an acceptable level?

⚠ Common exam trap

The SSCP exam often tests the distinction between risk mitigation (applying controls to reduce risk) and risk avoidance (eliminating the activity entirely), tricking candidates who think input validation removes the risk completely rather than reducing it to an acceptable level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk mitigation

Risk mitigation involves applying controls to reduce the likelihood or impact of a risk to an acceptable level. Implementing input validation and parameterized queries directly addresses the SQL injection vulnerability by preventing malicious SQL from being executed, thereby reducing the risk without eliminating the application's functionality.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk transfer

    Why it's wrong here

    Risk transfer shifts financial consequence to a third party such as an insurer; it does not alter the application's code or reduce exploitability. It is tempting because cyber-insurance policies do cover breach costs, making transfer the right response when residual risk is accepted commercially rather than remediated.

  • ✓

    Risk mitigation

    Why this is correct

    Input validation and parameterised queries remove the injection vector, so the SQL injection risk is reduced rather than transferred, avoided or accepted. Mitigation lowers likelihood or impact to a tolerable level, matching the stem's requirement to reduce risk to an acceptable level.

  • ✗

    Risk acceptance

    Why it's wrong here

    Risk acceptance documents the exposure and proceeds without additional controls, leaving the SQL injection exploitable. It is tempting because acceptance is legitimate for low-impact findings where remediation cost exceeds potential loss, but here input validation and parameterised queries actively lower the risk.

  • ✗

    Risk avoidance

    Why it's wrong here

    Risk avoidance eliminates the activity or asset generating the exposure entirely; patching the query code retains the web application and its database functionality. It is tempting because decommissioning the vulnerable feature would remove the SQL injection vector, which is the correct response when no control can reduce risk sufficiently.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.