mediumMultiple ChoiceObjective-mapped
SSCP Practice Question: A security team is implementing a risk treatment…
A security team is implementing a risk treatment plan for a high-risk vulnerability. The cost to fix the vulnerability is $100,000, but the expected loss if exploited is $1,000,000. The annual likelihood of exploitation is 2%. Which risk treatment strategy is most appropriate?
⚠ Common exam trap
ISC2 often tests the misconception that any high-severity vulnerability must be immediately remediated, ignoring the quantitative cost-benefit analysis that shows accepting risk can be the most appropriate strategy when the annualized loss is lower than the fix cost.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accept the risk and monitor for changes
The annualized loss expectancy (ALE) is $20,000 (2% × $1,000,000), which is less than the $100,000 remediation cost. Since the cost to fix exceeds the expected loss, accepting the risk and monitoring for changes is the most cost-effective strategy. This aligns with the risk management principle that treatment should be proportional to the risk exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Avoid the risk by decommissioning the asset
Why it's wrong here
Decommissioning may impact business operations.
- ✗
Remediate the vulnerability immediately
Why it's wrong here
Cost of remediation exceeds expected loss.
- ✓
Accept the risk and monitor for changes
Why this is correct
Expected loss is lower than remediation cost.
- ✗
Transfer the risk by purchasing cyber insurance
Why it's wrong here
Insurance premium may be significant and not eliminate risk.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 920-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.