Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementEasy

A small logistics company relies heavily on its proprietary inventory management system, which runs on an aging server. A recent vulnerability scan identified several critical unpatched vulnerabilities on this server. The company's IT budget is severely constrained, and replacing the server or implementing a robust patch management solution for legacy systems is currently unaffordable. The company decides to continue operating the system as is, acknowledging the risks but implementing no new countermeasures. Which risk management strategy is being applied?

  1. ARisk Mitigation
  2. BRisk Transfer
  3. CRisk Acceptance
  4. DRisk Avoidance
Show answer & explanation

Correct answer: C. Risk Acceptance

Risk acceptance occurs when an organization acknowledges a risk but chooses not to take action to reduce or eliminate it, often due to cost, business necessity, or low perceived impact. In this scenario, the company is aware of the vulnerabilities but has decided to continue operating without implementing new controls.

Why the other options are wrong

  • A. Risk mitigation involves taking steps to reduce the likelihood or impact of a risk.
  • B. Risk transfer involves shifting the burden of a risk to another party, often through insurance.
  • D. Risk avoidance means eliminating the activity or system that gives rise to the risk.

Risk Acceptance

A risk management strategy where an organization acknowledges a risk and decides to take no action to reduce or eliminate it, often due to cost-benefit analysis or business necessity.

  • No new controls are implemented.
  • Decision is often made after a cost-benefit analysis.
  • Can be passive (unaware) or active (informed choice).

Memory trick: Accepting risk is like shrugging off a minor threat.

More Risk Management questions