CompTIA Security+ (SY0-701)Security Program Management and OversightMedium
After reviewing a risk assessment, an organization's leadership decides that the cost of mitigating a low-probability, low-impact risk exceeds the potential loss, and no further action will be taken beyond monitoring. Which risk response strategy is being applied?
- ARisk avoidance
- BRisk transference
- CRisk acceptance
- DRisk mitigation
Show answer & explanationAnswer & explanation
Correct answer: C. Risk acceptance
Risk acceptance occurs when an organization decides to take no additional action to reduce a risk because the cost of treatment outweighs the potential benefit, choosing instead to acknowledge and monitor it.
Why the other options are wrong
- A. Risk avoidance means eliminating the activity that causes the risk entirely.
- B. Risk transference shifts the risk to a third party, such as through insurance.
- D. Risk mitigation involves implementing controls to reduce the risk, which was explicitly not done here.
Risk Acceptance
A risk response strategy where an organization decides to take no action to reduce a risk because the cost of treatment exceeds the potential impact.
- Often used for low-probability, low-impact risks
- Requires formal sign-off and documentation in the risk register
- Different from ignoring risk—it is a deliberate, documented decision
Memory trick: Accept, Avoid, Transfer, Mitigate—the four risk response verbs