SSCP Risk Identification, Monitoring, and Analysis Practice Question
An organization decides to outsource its data center operations to a cloud provider. The cloud provider is responsible for physical security and hardware maintenance. This is an example of which risk response strategy?
⚠ Common exam trap
SSCP often tests the confusion between risk transfer and risk mitigation, so candidates must recognize that outsourcing to a cloud provider is a transfer of operational risk, not an internal mitigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk transfer
Risk transfer involves shifting the financial impact of a risk to a third party, typically through insurance or outsourcing. By outsourcing data center operations to a cloud provider, the organization transfers the risks associated with physical security and hardware maintenance to the provider, making this a classic example of risk transfer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk acceptance
Why it's wrong here
Acceptance means acknowledging residual risk without transferring it; here the provider contractually absorbs physical security and hardware risk, which is transfer via outsourcing. It tempts because acceptance suits low-impact risks where no mitigation is cost-justified, but the stem describes shifting responsibility to a third party.
- ✓
Risk transfer
Why this is correct
Transferring data centre operations shifts physical security and hardware maintenance obligations to the cloud provider, moving that risk off the organisation's books via contract. This satisfies the stem's description precisely: the provider assumes responsibility, though residual accountability for data and compliance remains with the outsourcing organisation.
- ✗
Risk avoidance
Why it's wrong here
Risk avoidance means eliminating the activity that creates the risk entirely; outsourcing transfers the operational risk to the provider while the organisation still uses data centre services. It is tempting because the organisation stops running its own facility, and would be correct if it ceased data centre operations altogether.
- ✗
Risk mitigation
Why it's wrong here
Risk mitigation reduces the likelihood or impact of a threat while the organisation retains the activity and accountability; here the activity itself is transferred to the provider. It is tempting because controls such as physical security are applied, and would be correct if the organisation kept the data centre and added safeguards.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.