Certified In Cybersecurity CC · Free Practice Question Medium
Question 53
In the risk management process, which of the following best describes the concept of 'risk acceptance'?
-
A
Acknowledging that certain risks are too costly or impractical to mitigate and accepting the potential consequences
-
B
Implementing controls and countermeasures to eliminate all risks
-
C
Ignoring potential risks and their impacts
-
D
Avoiding the need for a risk management process
Reveal correct answer
Correct answer: A
Explanation
Risk acceptance is a component of the risk management process that involves recognizing when it may be more practical or cost-effective to accept a certain level of risk rather than attempting to eliminate it entirely (see ISC2 Study Guide, Domain 1). This decision is an informed choice typically based on the organization's risk appetite and on carefully analyzing the potential costs and benefits of implementing additional controls or countermeasures. By contrast, implementing controls and countermeasures to eliminate all risks, ignoring potential risks and their impacts, and avoiding the need for a risk management process are all incorrect options, as these approaches do not accurately describe the concept of informed choice underlying risk acceptance.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
