Governance & ComplianceQuestion 89 of 100
Choosing to take no action and knowingly bear a low-level risk is called:
a.Risk avoidance
b.Risk transference
c.Risk acceptance
d.Risk mitigation
Explanation
Risk acceptance is a conscious decision to tolerate a risk, usually when the cost of controls exceeds the potential loss. It should be formally documented and approved. Acceptance is appropriate for low-impact or low-likelihood risks.
Practice all 100 questions free — no signup required.
Related questions on this topic
- Which document outlines acceptable and prohibited uses of an organization's IT systems by employees?
- Which risk response involves purchasing insurance to shift financial impact to a third party?
- Eliminating a risky activity entirely so the risk no longer applies is known as:
- Which regulation governs the protection of personal data for individuals in the European Union?
- Which standard governs the secure handling of payment card data?
- Which US regulation protects the privacy and security of health information?
Last reviewed: · editorial process
PrepPass Editorial Team · Verified against CompTIA Security+ (SY0-701) · How we review