ISC2 Certified in Cybersecurity (CC) Practice Question
During risk treatment, which strategy involves selecting safeguards to lessen either the likelihood or impact of a threat without eliminating the activity that creates the risk?
The strategy described is mitigation. When an organization mitigates a risk, it implements controls-such as technical safeguards, administrative policies, or physical protections-to reduce the probability that the threat will be realized, the damage it can cause, or both. Mitigation keeps the activity in place but attempts to make it safer.
Avoidance takes the opposite approach by stopping or never starting the risky activity, thereby removing the exposure altogether. Transference shifts the financial responsibility for loss to another party (for example, through insurance or outsourcing). Acceptance means the organization consciously decides to tolerate the risk without further action, usually because the cost of additional controls would exceed the expected loss. Because only mitigation focuses on reducing likelihood or impact while allowing the activity to continue, it is the correct answer.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are examples of mitigation strategies in cybersecurity?
Open an interactive chat with Bash
How does mitigation differ from avoidance in risk treatment?
Open an interactive chat with Bash
When might an organization choose risk acceptance over mitigation?
Open an interactive chat with Bash
ISC2 Certified in Cybersecurity (CC)
Security Principles
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .