Triage BoardGet the app

Concept · Controls and risk

Risk responses: accept, transfer, avoid, mitigate

The CS0-004 exam recognizes four risk response strategies: accept the risk, transfer it, avoid it by dropping the activity, or mitigate it with controls. Objective 2.4 of the CS0-004 exam objectives pairs those four with three measures that decide which one fits: inherent risk, residual risk and risk appetite.

  • Exam code CS0-004
  • Tickets here 8

Four findings, four answers

A fictional logistics company works through four items at its quarterly risk review. The file-transfer server still needs an old protocol for one customer, so the team puts it behind segmentation and multifactor authentication (MFA). A marketing plan to collect customers' dates of birth is dropped after legal review. Card payments move to a payment provider under contract. A low-rated finding on a kiosk with no network connection is signed off by its business owner and stays as it is.

That is mitigate, avoid, transfer and accept, in that order. On the exam the wording is rarely that clean: the stem describes what the organization did, and you name the response from the effect. Ask what changed. If the likelihood or impact went down, it is mitigation. If the activity is gone, avoidance. If someone else now pays when it goes wrong, transfer. If nothing changed but a decision was recorded, acceptance.

The pair that causes the most hesitation is avoid against mitigate. Had the company switched the old protocol off and moved that customer to a modern one, the activity would be gone, which is avoidance. Restricting who can reach it lowers the likelihood but keeps the activity running, which is mitigation. Watch also for options that describe a contract as if it made the risk disappear: a contract moves the bill for a bad outcome, while the outcome can still happen.

What each response leaves behind

The four CS0-004 risk management strategies
ResponseWhat changesExample from the reviewWhat stays with you
AcceptNothing technical; the decision is recordedOffline kiosk finding signed offThe whole risk, and the duty to revisit it
TransferWho bears the costCard payments outsourced by contractAccountability and reputation
AvoidThe activity stopsBirth-date collection droppedNothing, and none of the benefit
MitigateLikelihood or impact dropsSegmentation and MFA on the serverResidual risk

From inherent to residual

Inherent riskbefore controlsControlsmitigationResidual riskwhat remainsWithinappetite?accept or treat
Controls turn inherent risk into residual risk; appetite decides whether that is low enough.

Inherent, residual, appetite

Inherent risk is the rating before any control. Take company laptops that hold customer records: lost or stolen, each one is a data exposure. Full-disk encryption brings that down sharply, yet some risk remains, for example a laptop taken while unlocked. That remainder is residual risk, and it is the number leadership actually signs off.

Risk appetite is how much risk the organization is willing to carry in pursuit of its goals. Residual risk inside the appetite can be accepted; residual risk above it needs more treatment or a decision to stop. Some question banks use risk tolerance for almost the same idea. Where both terms appear, appetite is the broad, organization-wide amount and tolerance the acceptable variation for one specific risk.

When the mitigating control stands in for a patch you cannot apply, it is a compensating control, and the exception that goes with it is a form of acceptance. Mitigation also happens before release: testing code with SAST, DAST and SCA lowers the likelihood that a flaw ships at all. An accepted risk is often the decision an executive summary asks leadership to make. The wider objective is on the controls and risk page.

“Ignore” is not a fifth responseTrap

An option where the organization does nothing and records nothing is unmanaged risk. Acceptance needs someone with authority over the asset to make the call and write it down. Distractors also offer “deny” or “defer”; neither is on the CS0-004 list.

Risk decisions on the desk

Registers and exception records turn up here. Treat each one as a decision someone will have to defend to an auditor.

Ticket 1 / 8

0 right

INC-001

In the process of developing a data protection strategy, a cybersecurity analyst must understand the extent of potential data breaches that the organization is prepared to handle. What term describes this concept?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Risk tolerance is the amount of loss or variation, such as breach impact, that the organization is prepared to handle; CS0-004 uses the broader term risk appetite for the overall willingness to take on risk, and since appetite is not offered, tolerance is the best fit.
  2. BRisk perception is how people subjectively judge a risk, not a limit the organization sets for itself.
  3. CRisk absorption is not a standard risk-management term; absorbing a loss is closer to accepting a risk than to defining how much the organization can handle.
  4. DRisk avoidance is a risk response that stops the risky activity altogether and does not measure how much breach impact the organization can absorb.

INC-002

When a vulnerability cannot be patched due to business constraints, which of the following is the MOST important documentation to maintain?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: A formal risk acceptance records who approved the remaining risk and which compensating controls reduce it, and it is the record auditors check when a patch cannot be applied.
  2. BAn email to the security team informs people but carries no approval authority, risk analysis or description of controls.
  3. CA vendor statement shows when a fix may arrive, but it does not record who accepted the risk in the meantime or how the risk is reduced.
  4. DA ticket note tracks the work item but lacks the formal approval and compensating-control detail an exception needs.

INC-003

An audit revealed a severely vulnerable legacy system was exploited because a previously approved security exception was never subsequently reviewed. Which governance failure directly caused this incident?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Exceptions should expire and be reviewed again; one that never comes up for review lets the risk and its compensating controls drift unchecked until the system is exploited.
  2. BWrong ownership can delay fixes, but here the exception was approved and then never reviewed, which is a lifecycle failure rather than an assignment failure.
  3. CGiving leadership raw counts is a weak reporting practice, but it is not what left this specific exception unreviewed.
  4. DMissing configuration detail weakens the record, yet even a well-documented exception becomes dangerous if nobody revisits it.

INC-004

A business unit requests an indefinite vulnerability exception for a legacy application without establishing a timeline for mitigation. What is the primary impact on the organization's audit readiness?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AAn open-ended exception does not force any upgrade; the problem is that nothing forces one.
  2. BCorrect: Without an expiration date or mitigation timeline, nobody is required to recheck the risk or prove the compensating controls still work, and that verification is exactly what auditors look for.
  3. CNo rule ties an exception to a host-based IDS; compensating controls are chosen for the specific risk instead of being mandated by the exception itself.
  4. DAn indefinite exception is an audit finding against the exception process and does not automatically fail unrelated perimeter assessments.

INC-005

Review the risk exception documentation matrix. Which legacy server's risk acceptance request is structurally complete and meets minimum audit requirements?

Exhibit

ServerRisk AcceptedCompensating ControlException DurationRemediation Plan
SRV-LEGACY-01SMBv1 RequiredNone currently applied12 MonthsMigrate to Server 2022 by Q4
SRV-HR-02Unsupported OSEDR installedIndefinitePending budget approval
SRV-FIN-03EOL DatabaseWAF and IPS rules applied6 MonthsUpgrade DB engine by Q3
SRV-APP-04Cleartext AuthVLAN SegmentationOngoingNone defined

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ASRV-APP-04 has an "Ongoing" duration and no remediation plan, so the exception never expires and has no exit path.
  2. BSRV-LEGACY-01 has a time limit and a plan but no compensating control, so the risk is accepted with nothing reducing it in the meantime.
  3. CCorrect: SRV-FIN-03 has every required element: compensating controls (WAF and IPS rules), a fixed 6-month duration and a dated remediation plan.
  4. DSRV-HR-02 has a compensating control (EDR), but its duration is indefinite and its plan depends on a budget that has not been approved.

INC-006

Which of the following equations can be used to calculate the Risk Exposure (RE) in a cybersecurity assessment?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ASubtracting likelihood from impact means a more likely threat would lower the exposure, which is backwards.
  2. BThis is circular: it defines risk exposure in terms of itself.
  3. CCorrect: Risk exposure is impact multiplied by likelihood, so an event that is both damaging and likely carries the greatest exposure.
  4. DDividing by likelihood would make more probable threats less risky, the opposite of how risk works.

INC-007

A retailer buys a cyber insurance policy to cover breach costs for its e-commerce platform. Which statement about this decision is accurate?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AAvoidance means stopping the risky activity; the platform keeps running, so the exposure still exists.
  2. BAcceptance means taking the risk on as is; buying insurance is an active step that shifts part of it.
  3. CCorrect: insurance shifts part of the financial impact to the insurer, while the retailer still answers for the breach.
  4. DInsurance does not reduce the likelihood of a breach, and no response brings residual risk to zero.

INC-008

Before any controls, a customer portal's risk is rated high. After the team adds a web application firewall and MFA, the rating drops to medium. What does the medium rating represent?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AInherent risk is the rating before controls, which here is the high rating.
  2. BCorrect: residual risk is what remains after controls are applied.
  3. CRisk appetite is how much risk the organization is willing to take on, not a measured rating after controls.
  4. DNothing was shifted to another party; the rating fell because controls were added.

Shift tally

0 / 0

Before you close this tab

  • Accept, transfer, avoid and mitigate are the four CS0-004 responses.
  • Name the response from its effect: lower likelihood or impact, no activity, someone else pays, or a recorded decision.
  • Inherent risk is rated before controls, residual risk after them.
  • Residual risk above the appetite needs more treatment; avoiding a risk gives up the activity's benefit too.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.