Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

During a risk assessment, a team identifies that a legacy inventory application has no vendor support and cannot be patched. Leadership decides to accept the risk because replacing the application would cost more than the potential loss. Which term best describes this decision?

⚠ Common exam trap

Many exam-takers confuse acceptance with doing nothing; acceptance is a documented, deliberate decision, while neglect is an unmanaged exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk acceptance

When leadership evaluates a risk and consciously decides to continue operating without adding controls because remediation costs outweigh expected losses, the decision is risk acceptance. This must be documented and periodically reviewed so it remains an informed choice. It differs from avoidance, which eliminates the activity, and from transference, which shifts financial impact to another party.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk transference

    Why it's wrong here

    Transference shifts the financial impact of a risk to another party, typically through insurance or contractual agreements. In this scenario, leadership is not purchasing insurance or outsourcing the liability; they are choosing to continue operating with the known risk. No third party assumes the loss, so transference does not describe the decision made for the legacy inventory application.

  • ✗

    Risk avoidance

    Why it's wrong here

    Avoidance means eliminating the risk entirely by discontinuing the activity or system that creates it. Leadership here explicitly keeps the legacy application running, so the risk remains. Avoidance would require decommissioning the inventory application or replacing it with a supported alternative. Because the organization continues to operate the vulnerable system, this is not avoidance.

  • ✗

    Risk mitigation

    Why it's wrong here

    Mitigation reduces the likelihood or impact of a risk through controls such as patching, segmentation, or monitoring. In this scenario no new controls are being applied to the unsupported application; the organization is simply choosing to live with the exposure. Because no risk-reducing action is taken, mitigation does not describe the leadership decision. Risk mitigation would require measures that lower the risk to an acceptable level.

  • ✓

    Risk acceptance

    Why this is correct

    Acceptance means the organization acknowledges the risk and chooses to proceed without additional mitigation because the cost of controls or replacement exceeds the expected loss. Leadership weighed the replacement cost against the potential loss and decided to retain the risk. Documenting this decision in the risk register, with a review date, is essential so the acceptance remains a conscious, accountable choice rather than neglect.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.