Courseiva
mediumMultiple ChoiceObjective-mapped

SSCP Practice Question: A security team is implementing a risk treatment…

A security team is implementing a risk treatment plan for a high-risk vulnerability. The cost to fix the vulnerability is $100,000, but the expected loss if exploited is $1,000,000. The annual likelihood of exploitation is 2%. Which risk treatment strategy is most appropriate?

⚠ Common exam trap

ISC2 often tests the misconception that any high-severity vulnerability must be immediately remediated, ignoring the quantitative cost-benefit analysis that shows accepting risk can be the most appropriate strategy when the annualized loss is lower than the fix cost.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Accept the risk and monitor for changes

The annualized loss expectancy (ALE) is $20,000 (2% × $1,000,000), which is less than the $100,000 remediation cost. Since the cost to fix exceeds the expected loss, accepting the risk and monitoring for changes is the most cost-effective strategy. This aligns with the risk management principle that treatment should be proportional to the risk exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Avoid the risk by decommissioning the asset

    Why it's wrong here

    Decommissioning may impact business operations.

  • Remediate the vulnerability immediately

    Why it's wrong here

    Cost of remediation exceeds expected loss.

  • Accept the risk and monitor for changes

    Why this is correct

    Expected loss is lower than remediation cost.

  • Transfer the risk by purchasing cyber insurance

    Why it's wrong here

    Insurance premium may be significant and not eliminate risk.

About these practice questions

This SSCP question is part of Courseiva's 920-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.