shieldCISSP Practice Domain 1 — Security and Risk Management Q11 of 120

Which type of risk response is being applied when a company purchases cyber-insurance to cover ransomware losses?

A CISSP practice question covering Domain 1: Security and Risk Management. Try answering before reading the explanation below.

Show options & answer
A
Risk avoidance
B
Risk acceptance
C
Risk transference
✓ Correct answer
D
Risk mitigation
Why "Risk transference" is the right answer

Insurance shifts financial loss to a third party — that is risk transference. Avoidance would mean dropping the activity entirely. Acceptance is doing nothing about the risk. Mitigation is reducing likelihood or impact through controls.

Study videos for this topic

Want to go deeper on Domain 1? Watch the full breakdown — every video is free, no account, no upsell.

Take the full CISSP practice test
120 questions, instant explanations, study-video links on every miss. No account.
Start full test →