TechKnowSurge
CompTIA Security+ 5.2 CompTIA Security+ 5.3 CompTIA CySA+ 2.5
InteractiveSecurityFree

Risk Management Strategy Selector

Classify business risk decisions as Avoid, Mitigate, Transfer, or Accept.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Every card here describes something an organization actually did about a risk, and the bin is that action, not the size of the risk or how urgent the sentence sounds. Four questions separate them cleanly. Did the organization stop doing the risky thing altogether? That is Avoid — and the tell is always that some business activity ends: card payments switched off, a product line discontinued, a BYOD rollout cancelled. Did it keep doing the activity but make the risk smaller? That is Mitigate — the WAF, the MFA rollout and the patch cycle all leave the business doing exactly what it was doing before, just with a lower likelihood or a smaller blast radius. Did it keep the activity and arrange for somebody else to absorb the cost? That is Transfer. Did it keep the activity, absorb the cost itself, and write that choice down? That is Accept. The trap this activity is built around is insurance. "Purchasing cyber liability insurance" feels protective, and protective feels like mitigation, so it is one of the most reliably missed items on the exam — but a policy does not make a breach any less likely and does not make it any smaller when it happens. It changes who pays. That is Transfer, and it is the definition rather than a technicality: transfer moves financial liability to a third party while leaving the underlying risk exactly where it was. The same test catches the two quieter transfer items. Outsourcing card processing to a PCI-certified vendor is not mitigation even though the vendor is genuinely better at it, because what moved is the liability for handling that data. A managed security services contract that includes breach response costs is transfer for the same reason — read the clause about who pays, not the part about who monitors. One caution worth carrying past the exam: transfer moves financial liability, never accountability. Regulators and customers still come to you after a breach, and the insurer's cheque does not answer to them. Acceptance is the other half of the vocabulary problem, and it is usually mistaken for its opposite. Accepting a risk is not ignoring one. Every Accept card in this set contains a decision and a record: the CISO documents that a low-probability, low-impact risk waits until next quarter; a small business compares a $5,000 remediation against the expected loss, decides the fix costs more than the risk, and logs it; a theoretical attack vector with no known exploits is recorded as accepted residual risk. Somebody with authority weighed it, chose to proceed, and left a trail. A risk nobody has noticed is not accepted, it is unmanaged — and the difference is the documentation. That is also why acceptance is the strategy every organization ends up using most: once you have avoided, mitigated and transferred what is worth the money, whatever is left is residual risk, and accepting it deliberately, within a stated risk appetite, is what finishing the process looks like.

What you'll learn

Aligned to

CompTIA Security+
5.2 Explain elements of the risk management process.
5.3 Explain the processes associated with third-party risk assessment and management.
CompTIA CySA+
2.5 Explain concepts related to vulnerability response, handling, and management.

Key terms

Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Risk Avoidance
A risk response strategy that eliminates exposure to a risk by choosing not to engage in the activity that creates it.
Risk Mitigation
The process of reducing the probability or potential impact of a risk through the implementation of controls, countermeasures, or process changes. Risk mitigation is one of four standard risk response strategies alongside avoidance, transfer, and acceptance.
Risk Transference
A risk response strategy that shifts the financial or operational burden of a risk to a third party, such as through insurance.
Risk Acceptance
A risk response strategy that acknowledges a risk and proceeds without additional mitigation because the benefits outweigh the potential harm.
Residual Risk
The level of risk that remains after security controls have been applied to reduce inherent risk. No control eliminates risk entirely; residual risk must be formally accepted by management or addressed with additional mitigations.
Risk Appetite
The overall level of risk a company is willing to accept in pursuit of its objectives, expressed as a general policy stance ranging from risk-taking to risk-averse.

Topics

Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →