SY0-701 Question 429
Single answerRisk toleranceA regional retail company is reviewing cybersecurity spending after several quarters of lower-than-expected revenue. A risk assessment shows that the company's public e-commerce site is vulnerable to automated credential-stuffing attacks, which could lead to account takeovers for a small percentage of customers. The security team recommends purchasing an advanced fraud-prevention platform, but the CFO decides the company will instead enforce stronger password requirements and monitor for suspicious login activity because the estimated financial impact is lower than the cost of the new platform. Which risk response best describes the CFO's decision?
- A
Risk avoidance
- B
Risk transference
- C
Risk mitigation
- D
Risk acceptance
Show answer and explanation
Correct answer: D
Explanation
This question focuses on risk tolerance in practice. Organizations rarely reduce every risk to zero; instead, they evaluate likelihood, impact, and cost of treatment to determine whether residual risk falls within acceptable limits. In this case, management reviewed the risk assessment, compared the probable financial impact to the cost of a more robust control, and decided to live with the remaining risk. That is risk acceptance. The fact that some compensating controls are still implemented does not change the overall response if leadership knowingly retains residual risk.
This aligns with common risk management guidance such as NIST SP 800-30 (Guide for Conducting Risk Assessments) and NIST SP 800-39 (Managing Information Security Risk), which describe how organizations assess risk, apply controls, and determine whether residual risk is acceptable based on organizational risk tolerance. From a Security+ perspective, candidates should distinguish between the presence of mitigating controls and the final management decision about whether the remaining risk is acceptable.
- A. Incorrect.
Risk avoidance would mean eliminating the activity that creates the risk, such as shutting down the online customer login functionality or changing the business process so credential-stuffing is no longer relevant. In this scenario, the company continues operating the e-commerce site and customer accounts, so the risk is not being avoided.
- B. Incorrect.
Risk transference would involve shifting some or all of the financial impact or operational burden to a third party, such as through cyber insurance or a managed service contract with defined liability terms. The scenario does not describe transferring the risk to another entity; it describes an internal business decision about what level of risk to retain.
- C. Incorrect.
Risk mitigation reduces the likelihood or impact of a threat through security controls. The stronger password requirements and login monitoring are mitigating controls, but the key point in the scenario is that leadership knowingly decides not to fully remediate the issue because the remaining exposure is considered tolerable relative to cost. That makes mitigation part of the approach, but not the primary risk response being tested here.
- D. Correct.
Risk acceptance is correct because the CFO evaluates the potential loss against the cost of additional controls and decides the organization can tolerate the remaining exposure. This is a classic example of risk tolerance driving a business decision: leadership accepts residual risk after implementing only cost-justified controls rather than pursuing the most comprehensive remediation.