Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

An organization decides to outsource its data center operations to a cloud provider. The cloud provider is responsible for physical security and hardware maintenance. This is an example of which risk response strategy?

⚠ Common exam trap

SSCP often tests the confusion between risk transfer and risk mitigation, so candidates must recognize that outsourcing to a cloud provider is a transfer of operational risk, not an internal mitigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk transfer

Risk transfer involves shifting the financial impact of a risk to a third party, typically through insurance or outsourcing. By outsourcing data center operations to a cloud provider, the organization transfers the risks associated with physical security and hardware maintenance to the provider, making this a classic example of risk transfer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk acceptance

    Why it's wrong here

    Acceptance means acknowledging residual risk without transferring it; here the provider contractually absorbs physical security and hardware risk, which is transfer via outsourcing. It tempts because acceptance suits low-impact risks where no mitigation is cost-justified, but the stem describes shifting responsibility to a third party.

  • ✓

    Risk transfer

    Why this is correct

    Transferring data centre operations shifts physical security and hardware maintenance obligations to the cloud provider, moving that risk off the organisation's books via contract. This satisfies the stem's description precisely: the provider assumes responsibility, though residual accountability for data and compliance remains with the outsourcing organisation.

  • ✗

    Risk avoidance

    Why it's wrong here

    Risk avoidance means eliminating the activity that creates the risk entirely; outsourcing transfers the operational risk to the provider while the organisation still uses data centre services. It is tempting because the organisation stops running its own facility, and would be correct if it ceased data centre operations altogether.

  • ✗

    Risk mitigation

    Why it's wrong here

    Risk mitigation reduces the likelihood or impact of a threat while the organisation retains the activity and accountability; here the activity itself is transferred to the provider. It is tempting because controls such as physical security are applied, and would be correct if the organisation kept the data centre and added safeguards.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.