ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a release-readiness meeting, a penetration-test report shows that application logs disclose internal file paths. Developers say fixing the logging code will take three weeks, but because only administrators can view the logs, the product owner proceeds with deployment and defers the fix. Which risk-treatment strategy is being applied?
Remediate the risk immediately by fixing the logging code before release.
Mitigate the risk by adding a web-application firewall rule.
By choosing to deploy without immediately correcting the logging issue-and instead documenting the exposure and planning to address it later-the organization is formally acknowledging and tolerating the risk. This is risk acceptance. No compensating controls (mitigation) are added, the flaw is not fixed before release (remediation), and the potential impact is not shifted to a third party (transfer).
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does risk acceptance mean in the context of cybersecurity?
Open an interactive chat with Bash
Why is documenting the risk decision significant during risk acceptance?
Open an interactive chat with Bash
How does risk acceptance differ from mitigation, remediation, or transfer?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Implementation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .