CompTIA Security+ (SY0-701)Security Program Management and OversightMedium

After reviewing a risk assessment, an organization's leadership decides that the cost of mitigating a low-probability, low-impact risk exceeds the potential loss, and no further action will be taken beyond monitoring. Which risk response strategy is being applied?

  1. ARisk avoidance
  2. BRisk transference
  3. CRisk acceptance
  4. DRisk mitigation
Show answer & explanation

Correct answer: C. Risk acceptance

Risk acceptance occurs when an organization decides to take no additional action to reduce a risk because the cost of treatment outweighs the potential benefit, choosing instead to acknowledge and monitor it.

Why the other options are wrong

  • A. Risk avoidance means eliminating the activity that causes the risk entirely.
  • B. Risk transference shifts the risk to a third party, such as through insurance.
  • D. Risk mitigation involves implementing controls to reduce the risk, which was explicitly not done here.

Risk Acceptance

A risk response strategy where an organization decides to take no action to reduce a risk because the cost of treatment exceeds the potential impact.

  • Often used for low-probability, low-impact risks
  • Requires formal sign-off and documentation in the risk register
  • Different from ignoring risk—it is a deliberate, documented decision

Memory trick: Accept, Avoid, Transfer, Mitigate—the four risk response verbs

More Security Program Management and Oversight questions