SSCP Comparison

Risk Avoidance vs Mitigation vs Transfer vs Acceptance

Acceptance must be explicit and authorized; informal tolerance is not governance.

Comparison Table

Risk Avoidance vs Mitigation vs Transfer vs Acceptance
OptionPrimary differenceBest use
AvoidanceStop the risky activityRetire a vulnerable unsupported system
MitigationReduce likelihood or impactPatch, segment, monitor, harden
TransferShift financial or contractual impactCyber insurance, outsourcing terms
AcceptanceApprove residual riskDocumented owner decision within tolerance

Exam clue: Acceptance must be explicit and authorized; informal tolerance is not governance.

How To Use It

Read the scenario for the required outcome. If the requirement is prevention, do not stop at detection. If the requirement is accountability, do not stop at authentication. If the requirement is recovery, distinguish data loss from service downtime.

Arcade Practice

Practice Adaptive SSCP Questions