ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
An analytics application runs on Amazon EC2 instances in a private subnet behind an Application Load Balancer. A vulnerability scan finds the OS is two minor versions behind (CVSS v3 score 3.1). Patching would require eight hours of downtime and cost USD 40 000. Management logs the issue in the risk register, postpones action until a migration in six months, and implements no immediate controls. Which risk-treatment strategy is being used?
Avoid the risk by decommissioning the EC2 instances and moving the workload off AWS
Transfer the risk by purchasing cyber-insurance to cover potential exploitation
Accept the risk and monitor it until the planned migration
Mitigate the risk immediately by scheduling the OS upgrade outside business hours
When an organization chooses to leave a known risk in place without adding new controls-because the risk is low, mitigation costs outweigh benefits, or it aligns with risk appetite-it is practicing risk acceptance. Here, management documents the vulnerability, defers action, and makes no immediate technical changes, demonstrating acceptance. Transfer would shift the risk to another party, mitigation would patch now, and avoidance would eliminate the workload entirely.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is meant by 'risk acceptance' in cybersecurity?
Open an interactive chat with Bash
What is the CVSS v3 score and how is it used in risk assessment?
Open an interactive chat with Bash
What factors should management consider before accepting a risk?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .