Certified In Cybersecurity CC · Free Practice Question Medium

Question 53

In the risk management process, which of the following best describes the concept of 'risk acceptance'?

  • A

    Acknowledging that certain risks are too costly or impractical to mitigate and accepting the potential consequences

  • B

    Implementing controls and countermeasures to eliminate all risks

  • C

    Ignoring potential risks and their impacts

  • D

    Avoiding the need for a risk management process

Reveal correct answer

Correct answer: A

Explanation

Risk acceptance is a component of the risk management process that involves recognizing when it may be more practical or cost-effective to accept a certain level of risk rather than attempting to eliminate it entirely (see ISC2 Study Guide, Domain 1). This decision is an informed choice typically based on the organization's risk appetite and on carefully analyzing the potential costs and benefits of implementing additional controls or countermeasures. By contrast, implementing controls and countermeasures to eliminate all risks, ignoring potential risks and their impacts, and avoiding the need for a risk management process are all incorrect options, as these approaches do not accurately describe the concept of informed choice underlying risk acceptance.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need