CompTIA Security+ (SY0-701)Security Program Management and OversightEasy

A company decides that the risk of operating an outdated third-party payment plugin is too high due to known vulnerabilities and a lack of vendor patches. Rather than accept, mitigate, or transfer the risk, the company removes the plugin entirely and switches to a different payment processing method. Which risk response strategy does this represent?

  1. ARisk mitigation
  2. BRisk transference
  3. CRisk acceptance
  4. DRisk avoidance
Show answer & explanation

Correct answer: D. Risk avoidance

Risk avoidance means eliminating the activity or condition that creates the risk entirely, such as discontinuing use of a vulnerable component. Mitigation reduces risk while keeping the activity, transference shifts risk to a third party, and acceptance means proceeding despite the risk.

Why the other options are wrong

  • A. Mitigation would keep the plugin but add compensating controls.
  • B. Transference shifts the risk (e.g., via insurance or a vendor contract), not applicable here.
  • C. Acceptance means continuing to use the plugin despite the risk.

Risk Avoidance

A risk response strategy that eliminates the risk by discontinuing the activity, process, or asset that creates it.

  • Removes the risk source entirely, not just its impact
  • Often used when mitigation costs exceed the value of the activity
  • Contrasts with acceptance, mitigation, and transference

Memory trick: Avoid it, Accept it, Transfer it, Mitigate it — AATM your risk.

More Security Program Management and Oversight questions