CompTIA Security+ (SY0-701)Security Program Management and OversightHard

An organization determines that fully mitigating a particular risk would cost more than the potential loss itself. Instead of implementing additional controls, the organization purchases a cyber insurance policy to cover potential financial losses from that risk. Which risk treatment strategy has been applied?

  1. ARisk mitigation
  2. BRisk avoidance
  3. CRisk acceptance
  4. DRisk transference
Show answer & explanation

Correct answer: D. Risk transference

Risk transference shifts the financial impact of a risk to a third party, such as through purchasing insurance, rather than reducing the likelihood or impact directly through controls.

Why the other options are wrong

  • A. Risk mitigation involves implementing controls to reduce risk, which the organization decided against due to cost.
  • B. Risk avoidance means eliminating the activity that causes the risk entirely, which was not done here.
  • C. Risk acceptance means taking no action and absorbing potential losses, whereas insurance shifts that burden elsewhere.

Risk Transference

A risk treatment strategy that shifts the financial or operational impact of a risk to a third party, commonly through insurance or outsourcing.

  • Common example: purchasing cyber insurance
  • Does not reduce likelihood or impact directly
  • Differs from acceptance, which retains the risk internally

Memory trick: Transfer the Bill to an Insurance Firm

More Security Program Management and Oversight questions