正解:A
When a risk is determined to be below the organization's risk appetite, the most appropriate course of action is to formally accept the risk. Risk acceptance is a valid and cost-effective strategy when the impact and likelihood are within acceptable limits, and the cost of mitigation outweighs the potential loss.
"Risk acceptance is an appropriate response when the level of residual risk is within the organization's defined risk tolerance and appetite."
- CISM Review Manual 15th Edition, Chapter 2: Risk Response and Mitigation* Avoidance, transfer, or mitigation may be overreactions that waste resources in this context.