A business unit keeps a low-priority legacy tool but adds extra monitoring and patching. The company also buys cyber insurance to reduce the financial effect of a loss. Which two risk treatment strategies are being used? Select two.
Mitigation reduces risk likelihood or impact through added controls, so extra monitoring and patching lower the legacy tool's exposure while the business unit retains it. This matches the stem's first treatment, distinct from the insurance-based transfer applied to financial loss.
Why this answer
Mitigation (B) is correct because the business unit keeps the legacy tool but reduces its risk exposure by adding extra monitoring and patching, which are compensating controls that lower the likelihood or impact of a loss. Transfer (D) is correct because purchasing cyber insurance shifts the financial consequences of a potential loss to the insurer, which is the defining characteristic of risk transfer. Acceptance (A) does not apply because the organization is actively applying controls rather than simply acknowledging and retaining the risk without action.
Avoidance (C) does not apply because the legacy tool is still kept in use rather than being eliminated or discontinued. Deterrent (E) is not a distinct risk treatment strategy here; monitoring and patching are preventive/detective controls supporting mitigation, not a separate deterrent strategy.
Exam trap
The trap here is that candidates may confuse risk acceptance (keeping the asset without additional controls) with risk mitigation (adding controls), or they may fail to recognize that cyber insurance is a transference strategy, not mitigation or acceptance.