200-201 Security Concepts Practice Question
A security analyst is evaluating the risk of a new vulnerability in a web application. The vulnerability has a CVSS base score of 9.8 and is remotely exploitable without authentication. The application is internet-facing and processes sensitive customer data. Which risk response strategy is MOST appropriate according to risk management principles?
⚠ Common exam trap
The trap here is choosing risk transference (e.g., cyber insurance) as a quick fix, but it does not address the underlying vulnerability and is not the primary response for high-severity technical risks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk mitigation
The vulnerability is critical and remotely exploitable, posing a high risk to sensitive data. Mitigating the risk through patching or other controls is the most appropriate response. Risk acceptance, transference, or avoidance are less suitable because they do not directly reduce the technical exposure in a timely manner.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk transference
Why it's wrong here
Risk transference shifts the risk to a third party, such as through insurance or outsourcing. While cyber insurance can help with financial impact, it does not address the technical vulnerability. Transference is not a primary strategy for actively exploited, high-severity vulnerabilities in critical systems.
- ✗
Risk avoidance
Why it's wrong here
Risk avoidance means eliminating the risk by discontinuing the activity. For an internet-facing application processing sensitive data, avoidance might involve shutting it down, which is often impractical and not the best first step. Mitigation is preferred to maintain business operations while reducing risk.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance means acknowledging the risk and taking no action, which is inappropriate for a critical vulnerability with a high likelihood and impact. Accepting such a risk could lead to a severe data breach. Risk acceptance is typically reserved for low-risk issues where the cost of mitigation exceeds the potential loss.
- ✓
Risk mitigation
Why this is correct
Risk mitigation involves applying controls to reduce the likelihood or impact of a vulnerability. Given the high CVSS score and exposure, patching or implementing a web application firewall is necessary. Mitigation is the most appropriate response to protect sensitive data and maintain compliance.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.