If you have started working through the risk management material for SY0-701, you have probably hit a question that hands you a perfectly reasonable scenario and four answers that all sound responsible. A company did something about a risk, and you just have to name what they did. That is exactly where a lot of people lose points, because the four risk responses are easy to define and surprisingly easy to misapply once the scenario is wrapped in business language.
Here are the four, in plain terms.
Avoidance
You stop doing the thing that creates the risk. No half measures, no extra controls bolted on top. If running a legacy app is too dangerous, you decommission it. If a feature exposes customer data you cannot protect, you cut the feature. Avoidance removes the activity itself, not just the danger around it.
Mitigation
You keep the activity but reduce the likelihood or the impact. This is where most security controls live: patching, firewalls, MFA, backups, awareness training. Mitigation is the default response, which is exactly why the exam likes to dangle it as the obvious answer when the correct choice is actually one of the others.
Transference (also called sharing)
You shift the financial consequences to someone else. The classic example is cyber insurance. Another is outsourcing a risky function to a third party that contractually owns the outcome. Notice what transference does not do: it does not lower the chance of the event happening. Your data can still be breached. You have only arranged for someone else to absorb part of the cost.
Acceptance
You acknowledge the risk and choose to live with it, usually because treating it would cost more than the expected loss. On the exam, acceptance is often correct when the scenario says a risk is low, or that remediation is too expensive to justify. Formal acceptance also tends to involve sign-off from someone with the authority to own that decision, which is a detail worth remembering.
The trap
The single most missed version of this question is the insurance one. A company buys a cyber insurance policy to cover breach costs. Which response is that? Plenty of people read "doing something proactive about a breach" and pick mitigation. It is transference. Insurance does nothing to reduce how likely the breach is or how severe the technical impact will be. It only moves who pays. If you train yourself to ask one question, "did this actually lower likelihood or impact, or did it just move the cost," you will get these right almost every time.
A few more distinctions the exam leans on:
- Avoidance versus mitigation. Mitigation keeps the activity alive with controls around it. Avoidance ends the activity. If the scenario says the company "stopped offering," "removed," or "discontinued," lean avoidance. If it says "added," "implemented," or "deployed," lean mitigation.
- Transference versus mitigation. Outsourcing can look like mitigation because a vendor may genuinely be more secure. For the exam, focus on where the consequence lands. If a contract or a policy is shifting cost or liability, that is transference.
- Acceptance versus ignoring. Acceptance is a decision. Someone looked at the risk, weighed it, and signed off. Ignoring a risk that nobody ever assessed is not acceptance, it is negligence, and the exam will sometimes word an answer to test whether you know the difference.
There is also a related idea you will see in some materials: an exemption or exception, where a specific system is formally allowed to run outside a policy for a documented reason. It behaves like a scoped acceptance. If it shows up, treat it as a documented decision to live with a known gap.
Why this rewards practice instead of memorizing
Definitions alone will not save you here. You can recite all four perfectly and still pick the wrong one when the action is buried in corporate phrasing. The fix is to see enough varied scenarios that the pattern becomes automatic: read the action, ask whether it changed the probability or the impact or only moved the cost, then match it to the response.
That is the kind of pattern drilling I built into SecPlus Mastery. The practice questions deliberately put mitigation next to transference and acceptance so you stop defaulting to the obvious-sounding choice. If you want to see where you actually stand on risk management before committing to a study plan, the free diagnostic at secplusmastery.com/diagnostic will show you which domains are solid and which ones still need work.
One last way to lock it in. Take a single real decision from your own life or job, maybe a backup you set up or a subscription you canceled, and label it with the correct risk response. The skill the exam is testing is not memorizing four words. It is reading a situation and naming what was actually done. Get comfortable doing that out loud, and the risk questions turn from guesswork into free points.
Top comments (0)