nerdexam
CompTIA

CAS-001 · Question #79

A Chief Information Security Officer (CISO) has been trying to eliminate some IT security risks for several months. These risks are not high profile but still exist. Furthermore, many of these risks…

The correct answer is C. Accept the risks. Risk acceptance (also called risk tolerance or risk retention) is the appropriate strategy when: the risks are not high-profile (low impact/likelihood), innovative mitigation has already been applied where possible, and the remaining budget is insufficient for further action…

Enterprise Security

Question

A Chief Information Security Officer (CISO) has been trying to eliminate some IT security risks for several months. These risks are not high profile but still exist. Furthermore, many of these risks have been mitigated with innovative solutions. However, at this point in time, the budget is insufficient to deal with the risks. Which of the following risk strategies should be used?

Options

  • ATransfer the risks
  • BAvoid the risks
  • CAccept the risks
  • DMitigate the risks

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    2% (1)
  • C
    88% (37)
  • D
    5% (2)

Explanation

Risk acceptance (also called risk tolerance or risk retention) is the appropriate strategy when: the risks are not high-profile (low impact/likelihood), innovative mitigation has already been applied where possible, and the remaining budget is insufficient for further action. Accepting risk means formally acknowledging the residual risk and consciously choosing not to invest additional resources at this time, typically with documentation and executive sign-off. Risk transfer (insurance/contracts) costs money the budget doesn't have. Risk avoidance means stopping the activity entirely, which may not be feasible. Further mitigation requires budget that doesn't exist. Acceptance is the pragmatic choice under these constraints.

Topics

#risk acceptance#risk management strategy#budget constraints#residual risk

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice