nerdexam
EC-Council

312-50V13 · Question #11

Suppose your company has just passed a security risk assessment exercise. The results display that the risk of the breach in the main company application is 50%. Security staff has taken some…

The correct answer is A. Accept the risk. When a risk's probability is below the established acceptable threshold after mitigation, the most business-profitable decision is to accept the remaining risk.

Submitted by helene.fr· Mar 6, 2026Information Security and Ethical Hacking Overview

Question

Suppose your company has just passed a security risk assessment exercise. The results display that the risk of the breach in the main company application is 50%. Security staff has taken some measures and implemented the necessary controls. After that, another security risk assessment was performed showing that risk has decreased to 10%. The risk threshold for the application is 20%. Which of the following risk decisions will be the best for the project in terms of its successful continuation with the most business profit?

Options

  • AAccept the risk
  • BIntroduce more controls to bring risk to 0%
  • CMitigate the risk
  • DAvoid the risk

How the community answered

(48 responses)
  • A
    79% (38)
  • B
    2% (1)
  • C
    6% (3)
  • D
    13% (6)

Why each option

When a risk's probability is below the established acceptable threshold after mitigation, the most business-profitable decision is to accept the remaining risk.

AAccept the riskCorrect

The risk has been reduced to 10%, which is below the company's established risk threshold of 20%. Since the risk is now within acceptable limits and further mitigation to 0% is often unfeasible or too costly, accepting the remaining risk is the most cost-effective decision for project continuation and business profit.

BIntroduce more controls to bring risk to 0%

It is generally impossible or economically prohibitive to bring any risk down to 0%, as security controls always have associated costs and limitations.

CMitigate the risk

Mitigating the risk has already been successfully performed, reducing it to an acceptable level; the question asks for the best decision *now* based on the acceptable residual risk.

DAvoid the risk

Avoiding the risk would mean discontinuing the project or application, which contradicts the goal of 'successful continuation with the most business profit' given the risk is now acceptable.

Concept tested: Risk management strategies (Accept, Mitigate, Avoid, Transfer)

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/secure/security-governance-risk-compliance-strategy

Topics

#risk management#risk acceptance#risk threshold#security controls

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice