nerdexam
IIA

IIA-CIA-PART1 · Question #16

A risk assessment showed that the cost of addressing a particular risk in the organization's human resources department is greater than the perceived benefit. Which risk response approach should the…

The correct answer is B. Transfer the risk. Note: The marked correct answer (B) appears to be incorrect based on standard risk management principles. The correct answer for this scenario is C - Accept the risk. When a cost-benefit analysis shows that addressing a risk costs more than the benefit gained from mitigating…

Question

A risk assessment showed that the cost of addressing a particular risk in the organization's human resources department is greater than the perceived benefit. Which risk response approach should the organization take in this scenario?

Options

  • AReduce the risk.
  • BTransfer the risk.
  • CAccept the risk.
  • DShare the risk.

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    75% (21)
  • C
    7% (2)
  • D
    14% (4)

Explanation

Note: The marked correct answer (B) appears to be incorrect based on standard risk management principles. The correct answer for this scenario is C - Accept the risk.

When a cost-benefit analysis shows that addressing a risk costs more than the benefit gained from mitigating it, the standard response is to accept the risk - acknowledge it exists and take no further action, because intervention isn't economically justified. Reducing the risk (A) involves implementing controls, which still incurs costs that the scenario says aren't worth it. Transferring the risk (B) shifts it to a third party (e.g., insurance), but this also carries a cost and is chosen when you want to offload liability, not when the math says doing anything isn't worth it. Sharing the risk (D) is a form of transfer involving joint responsibility and still requires resource expenditure.

Memory tip: Think of "Accept" as the "do nothing" option - it's always the right choice when the cure is more expensive than the disease. If cost > benefit, accept and move on.


If this question came from a study guide or practice exam, I'd recommend flagging it as potentially mislabeled - most PMBOK, CompTIA Security+, CRISC, and ISO 31000 frameworks would mark C as correct here.

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART1 Practice