CompTIA CySA+ (CS0-003) — Question 305
Which of the following risk management decisions should be considered after evaluating all other options?
Answer options
- A. Transfer
- B. Acceptance
- C. Mitigation
- D. Avoidance
Correct answer: B
Explanation
The correct answer is B, Acceptance, as it represents the decision to acknowledge the risk once all other strategies have been considered. Transfer, Mitigation, and Avoidance are proactive measures that aim to reduce or eliminate the risk, which should be evaluated first.