nerdexam
(ISC)2

CCSP · Question #722

Which of the following terms is NOT a commonly used category of risk acceptance?

The correct answer is D. Accepted. Minimal, Moderate, and Critical (or High) are standard risk severity/level categories used to classify and prioritize risks. 'Accepted' is not a risk level category - it is a risk treatment or response strategy (i.e., the decision to accept a risk rather than mitigate…

Submitted by kev92· Apr 18, 2026Legal, Risk and Compliance

Question

Which of the following terms is NOT a commonly used category of risk acceptance?

Options

  • AModerate
  • BCritical
  • CMinimal
  • DAccepted

How the community answered

(24 responses)
  • A
    4% (1)
  • C
    8% (2)
  • D
    88% (21)

Explanation

Minimal, Moderate, and Critical (or High) are standard risk severity/level categories used to classify and prioritize risks. 'Accepted' is not a risk level category - it is a risk treatment or response strategy (i.e., the decision to accept a risk rather than mitigate, transfer, or avoid it). Confusing a risk treatment action with a risk classification category is a common distractor on security exams.

Topics

#Risk Acceptance#Risk Management#Risk Categories#Risk Treatment

Community Discussion

No community discussion yet for this question.

Full CCSP Practice