CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityEasy

A startup's risk register flags a minor risk: a rarely used internal reporting dashboard could be briefly unavailable during maintenance windows. The cost of adding redundancy far exceeds the potential business impact, so leadership formally documents the risk and decides to take no further action, monitoring it periodically. Which risk response strategy is being used?

  1. ARisk acceptance
  2. BRisk avoidance
  3. CRisk transfer
  4. DRisk mitigation
Show answer & explanation

Correct answer: A. Risk acceptance

Risk acceptance means the organization acknowledges a risk and consciously decides to take no additional action because the cost of treatment outweighs the potential impact, while still documenting and monitoring it. Avoidance would eliminate the activity, mitigation would reduce likelihood/impact, and transfer would shift the risk to a third party.

Why the other options are wrong

  • B. Avoidance would mean eliminating the dashboard or activity entirely, not just documenting it.
  • C. Transfer would involve insurance or a third party absorbing the risk, not documentation alone.
  • D. Mitigation requires implementing controls to reduce the risk, which was explicitly not done here.

Risk Acceptance

A risk response strategy where an organization decides to tolerate a low-impact or low-probability risk without further treatment, after documenting the decision.

  • Used when treatment cost exceeds potential impact
  • Risk is still tracked/monitored, not ignored
  • One of four standard risk response strategies alongside avoidance, mitigation, and transfer

Memory trick: A-M-T-A: Avoid, Mitigate, Transfer, Accept the risk.

More Governance, Risk, Compliance and Security questions