Courseiva

CCNA Risk Response and Mitigation Questions

19 of 94 questions · Page 2/2 · Risk Response and Mitigation · Answers revealed

76
MCQeasy

Based on the exhibit, what is the primary risk response strategy demonstrated by this firewall rule?

A.Risk Transfer
B.Risk Acceptance
C.Risk Mitigation
D.Risk Avoidance
AnswerC

The firewall blocks specific IP ranges, reducing the probability of attacks.

Why this answer

The firewall rule denies inbound traffic on TCP port 443 (HTTPS) from any source to any destination. This directly reduces the attack surface by blocking a specific protocol, which is a classic risk mitigation action. By implementing a technical control to reduce the likelihood or impact of a threat, the organization is applying risk mitigation, not transferring, accepting, or avoiding the risk entirely.

Exam trap

The trap here is confusing risk mitigation (reducing risk with controls) with risk avoidance (eliminating the risk by ceasing the activity), as candidates often think blocking a port is 'avoiding' the risk when it is actually reducing it while the underlying service remains operational.

How to eliminate wrong answers

Option A is wrong because risk transfer involves shifting the financial impact of a risk to a third party (e.g., insurance or outsourcing), not implementing a firewall rule. Option B is wrong because risk acceptance means formally acknowledging the risk without taking action to reduce it, whereas this rule actively reduces exposure. Option D is wrong because risk avoidance would mean eliminating the activity or asset that creates the risk (e.g., decommissioning the web server entirely), not just blocking a specific port.

77
MCQhard

A healthcare organization's risk register shows that a critical server lacks vendor support and has a high inherent risk of failure. The risk owner proposes to implement redundant hardware and a failover cluster. The cost of the redundancy is $200,000, while the estimated annual loss from failure is $150,000. Which factor is MOST important for the risk practitioner to consider when evaluating this proposed risk response?

A.The likelihood of the server failing in the next year
B.The cost of the control compared to the expected loss
C.The risk tolerance of the IT department
D.The residual risk after implementing the redundancy
AnswerB

The fundamental principle of risk response is that the cost of mitigation should not exceed the expected loss. Here, the control costs $200,000 annually while the expected loss is $150,000, indicating a negative return on security investment. The risk practitioner should recommend a more cost-effective solution or consider risk acceptance, as the proposed redundancy is not economically justified based on the given figures.

Why this answer

The risk practitioner must perform a cost-benefit analysis. The proposed control costs $200,000, while the expected annual loss is $150,000, meaning the control costs more than the risk it mitigates. Unless there are intangible or regulatory factors, the response is not cost-effective.

The most important factor is the comparison of control cost to expected loss, which guides whether to mitigate, accept, or seek a cheaper alternative.

Exam trap

The trap here is focusing on residual risk or likelihood without performing the cost-benefit calculation that reveals the control is more expensive than the potential loss.

78
MCQeasy

A recent security assessment identified that a critical web application is vulnerable to SQL injection due to unpatched software. The vendor has released a security patch. Which risk response is most appropriate?

A.Mitigate by applying the patch
B.Avoid by taking the application offline
C.Accept the risk
D.Transfer via insurance
AnswerA

Applying the vendor patch removes the unpatched-software condition enabling SQL injection, reducing likelihood and impact to acceptable levels. Mitigation is appropriate because a known, available fix exists, satisfying the assessment finding rather than transferring, avoiding or accepting the risk.

Why this answer

Applying the vendor-released patch directly reduces the likelihood and impact of the SQL injection vulnerability, which is the definition of risk mitigation. Since a patch exists and the application is critical, mitigation is both feasible and the most appropriate response — it addresses the root cause rather than avoiding, accepting, or transferring the consequence.

Exam trap

CRISC often tests the distinction between mitigation and avoidance — candidates pick 'take offline' thinking it is the safest response, but avoidance is only appropriate when the risk cannot be mitigated cost-effectively.

How to eliminate wrong answers

Option B is wrong because taking a critical application offline is risk avoidance, which is disproportionate — it eliminates the risk by eliminating the business function, causing unacceptable operational impact when a patch is available. Option C is wrong because accepting the risk is inappropriate for a critical application with a known, patchable SQL injection vulnerability — acceptance is reserved for low-impact risks or when no cost-effective response exists. Option D is wrong because transferring via insurance compensates financial loss after an incident but does not prevent the SQL injection from occurring or protect the data — it is a financial response, not a technical control.

79
Multi-Selectmedium

Which THREE of the following are key considerations when selecting a risk response option?

Select 3 answers
A.Cost-benefit analysis of controls
B.Impact of the risk without controls
C.Risk appetite of the organization
D.Current control effectiveness
E.Legal and regulatory requirements
AnswersA, C, E

Cost-effectiveness is crucial.

Why this answer

A cost-benefit analysis of controls (Option A) is a key consideration because it ensures that the cost of implementing a risk response (e.g., a technical control like an intrusion prevention system or encryption) does not exceed the value of the asset being protected or the expected reduction in risk. This aligns with the principle of cost-effective risk mitigation, where the residual risk must be acceptable relative to the investment.

Exam trap

The trap here is that candidates confuse factors used in risk assessment (like impact without controls or current control effectiveness) with factors used in risk response selection, which specifically requires evaluating organizational appetite, cost-benefit, and mandatory legal/regulatory obligations.

80
MCQeasy

A small e-commerce company has identified a high-risk vulnerability in its payment processing system that could expose customer credit card data. The IT team recommends immediately patching the system, but the patch requires a 4-hour downtime during peak sales hours. The risk manager proposes accepting the risk until the next scheduled maintenance window in two weeks. The CEO is concerned about potential fines from PCI DSS non-compliance. What is the BEST course of action?

A.Delay the patch until the next maintenance window but document the risk acceptance with CEO sign-off.
B.Accept the risk and schedule the patch during the next maintenance window as originally planned.
C.Apply the patch immediately during peak hours, accepting the revenue loss from downtime.
D.Implement a compensating control (e.g., web application firewall) and schedule the patch during off-peak hours within 48 hours.
AnswerD

A web application firewall filters malicious traffic while the patch is deferred, reducing exposure during the two-week gap, and off-peak patching within 48 hours restores compliance faster than the maintenance window. This satisfies the PCI DSS and downtime constraints simultaneously.

Why this answer

The best course of action balances risk mitigation, business continuity, and compliance. Implementing a compensating control such as a web application firewall reduces the immediate exposure of the vulnerability while allowing the patch to be scheduled during off-peak hours within a short timeframe (48 hours), avoiding both peak-hour downtime and prolonged exposure. This aligns with CRISC's emphasis on risk response options that are proportionate and timely, and it addresses the CEO's PCI DSS compliance concern by reducing the window of non-compliance.

Exam trap

CRISC often tests whether candidates default to 'accept the risk' or 'patch immediately' when the correct answer is a balanced compensating control that addresses both risk and business impact.

How to eliminate wrong answers

Option A is wrong because delaying the patch for two weeks with only documented risk acceptance leaves the payment system exposed to a high-risk vulnerability for an extended period, which is not proportionate given the PCI DSS exposure and the availability of a compensating control. Option B is wrong because simply accepting the risk without any mitigation ignores the severity of the vulnerability and the compliance implications, and 'accept' is the weakest of the four risk responses when a high-risk issue affects cardholder data. Option C is wrong because applying the patch immediately during peak hours causes unnecessary revenue loss and business disruption when a compensating control plus off-peak patching achieves the same risk reduction with far less impact.

81
MCQeasy

A software development company identifies that developers are storing API keys in plaintext within source code repositories. The risk practitioner proposes a risk treatment plan that includes implementing a secrets management solution and rotating all exposed keys. The Chief Technology Officer asks how the risk practitioner will confirm that the treatment plan is reducing the risk over time. Which metric is MOST appropriate for monitoring the effectiveness of this risk response?

A.The number of secrets detected in source code repositories during automated scans each sprint.
B.The percentage of developers who have completed secure coding training in the last year.
C.The mean time to rotate API keys after a developer reports a suspected exposure.
D.The total number of API keys currently managed by the secrets management solution.
AnswerA

Automated scanning for secrets in source code directly measures whether developers are still storing credentials insecurely. A downward trend in detected secrets indicates the secrets management solution and training are working. This metric is leading and actionable, allowing the risk practitioner to track the effectiveness of the treatment plan over time and address recurring issues in specific teams or repositories.

Why this answer

The most appropriate metric directly measures whether the risky behavior is decreasing. Automated scans for secrets in source code provide objective, recurring evidence of plaintext credentials. A declining trend confirms the secrets management solution and process changes are effective.

Metrics such as total managed keys, rotation time, and training completion are indirect or reactive and do not demonstrate that insecure storage has been reduced over time.

Exam trap

The trap here is choosing a metric that measures tool adoption or training completion instead of the actual reduction of insecure secrets in code.

82
MCQmedium

A risk manager is reviewing the risk treatment plan for a new mobile banking application. The plan includes implementing multi-factor authentication (MFA) and conducting regular vulnerability scans. The risk manager wants to ensure that the controls are operating effectively. Which of the following should be performed to verify the effectiveness of the controls?

A.Gap analysis
B.Business impact analysis (BIA)
C.Control testing
D.Risk assessment
AnswerC

Control testing involves evaluating whether controls are designed and operating effectively. It can include walkthroughs, inspections, and re-performance. For MFA and vulnerability scans, testing might involve attempting to bypass MFA or reviewing scan reports to ensure they are complete and timely. This provides assurance that the controls are functioning as intended and mitigating the risk.

Why this answer

To verify that controls are operating effectively, the risk manager should perform control testing. This involves examining and testing the controls to ensure they are implemented correctly and functioning as intended. Risk assessment, gap analysis, and BIA serve different purposes and do not provide assurance on control effectiveness.

Exam trap

The trap here is confusing control testing with risk assessment; risk assessment identifies risks, but control testing verifies that controls mitigate those risks effectively.

83
Multi-Selectmedium

Which TWO of the following are examples of risk transfer? (Select TWO.)

Select 2 answers
A.Outsourcing IT operations to a third party
B.Implementing encryption
C.Accepting residual risk
D.Buying cyber insurance
E.Conducting security training
AnswersA, D

Outsourcing shifts operational risk to the vendor under contract, so liability for failures transfers rather than being mitigated or avoided. This satisfies the stem's risk transfer definition by moving financial consequence to a third party.

Why this answer

Option A (Outsourcing IT operations to a third party) is correct because risk transfer shifts the financial and operational impact of a risk to another entity via a contractual agreement, such as an SLA or MSA, where the vendor assumes responsibility for the outsourced functions. Option D (Buying cyber insurance) is correct because insurance is the classic form of risk transfer, where the insurer agrees to compensate the organization for covered losses in exchange for premiums, moving the financial consequence of the risk to the insurer. Option B (Implementing encryption) is a risk mitigation or reduction control that lowers the likelihood or impact of a data breach rather than transferring it.

Option C (Accepting residual risk) is risk acceptance, where the organization retains the remaining risk after other treatments. Option E (Conducting security training) is also risk mitigation, reducing human error and improving security awareness rather than shifting risk to a third party.

Exam trap

The distinction between risk transfer and risk mitigation is frequently tested on the CRISC exam. Candidates often confuse controls like encryption or training with transfer mechanisms, when in fact only insurance and outsourcing (with liability transfer) qualify as true risk transfer.

84
MCQhard

A healthcare organization is migrating its electronic health records (EHR) system to a cloud provider. The risk assessment shows that the cloud provider has strong security certifications (e.g., SOC 2 Type II, ISO 27001). However, the organization's legal team is concerned about data sovereignty laws that require patient data to remain within the country. The cloud provider's data centers are located in three regions: one in-country, and two outside. The project manager proposes using only the in-country data center. The IT director warns that this will increase latency and reduce redundancy. The risk manager must propose a response. Which is the BEST option?

A.Accept the legal risk because the cloud provider's certifications are sufficient, and document the decision.
B.Use all three data centers with automatic failover, and rely on the cloud provider's contractual guarantees of data residency.
C.Configure the EHR system to store primary data in the in-country data center, and use the other two centers for disaster recovery with data residency controls ensuring data does not leave the country unless encrypted and with legal approval.
D.Use only the in-country data center and accept the increased availability risk.
AnswerC

This option balances compliance by storing primary data in-country and using other centers for DR with data residency controls, addressing both legal and availability concerns.

Why this answer

It balances compliance with data sovereignty laws (using the in-country data center for primary storage) and maintains redundancy for disaster recovery with data residency controls. Option A is wrong because simply accepting the legal risk based on certifications is not sufficient; data sovereignty laws are regulatory requirements that must be adhered to, and the certifications do not override those laws. Option B is wrong because automatic failover to data centers outside the country would violate data sovereignty laws by allowing patient data to leave the country without proper controls.

Option D is wrong because using only one data center increases availability risk and does not address the legal concerns properly; it avoids the legal risk but introduces high operational risk.

85
Matchingmedium

Match each risk management term to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Risk level before controls are applied

Risk level after controls are applied

Amount of risk the organization is willing to accept

Acceptable deviation from risk appetite

Why these pairings

The correct matches are Risk with 'effect of uncertainty on objectives', Threat with 'circumstance/event that can adversely impact', and Vulnerability with 'weakness that can be exploited'. Common confusions include swapping definitions between these terms.

86
MCQmedium

A financial services firm has determined that a critical trading application cannot be patched for a known remote code execution vulnerability because the vendor no longer supports the platform. The risk manager decides to deploy a web application firewall (WAF) with virtual patching and network segmentation to isolate the application from the internal network. Which risk response strategy does this represent?

A.Risk acceptance
B.Risk transfer
C.Risk mitigation
D.Risk avoidance
AnswerC

Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. Deploying a WAF with virtual patching and network segmentation directly reduces the exploitability of the unpatched application and limits lateral movement, thereby lowering the overall risk. This aligns with the organization's decision to take action rather than transfer, avoid, or accept the risk.

Why this answer

The organization is actively reducing the likelihood and impact of a vulnerability by deploying a WAF and network segmentation. These compensating controls are classic risk mitigation actions. Risk mitigation is the appropriate strategy when an organization chooses to implement controls to bring residual risk within appetite rather than accepting, transferring, or avoiding the risk entirely.

Exam trap

The trap here is confusing risk mitigation with risk avoidance because compensating controls are used instead of removing the vulnerable system.

87
Multi-Selectmedium

A retail company is launching a new e-commerce platform. The risk management team has identified that the platform's payment gateway integration could be exploited to intercept customer credit card data. The team proposes several controls. Which of the following are examples of risk mitigation controls? (Choose two.)

Select 2 answers
A.Encrypting payment data in transit using TLS 1.3
B.Purchasing cyber insurance to cover financial losses from a data breach
C.Deciding not to accept credit card payments online
D.Outsourcing the payment processing to a third-party provider
E.Implementing tokenization to replace sensitive card data with non-sensitive equivalents
AnswersA, E

Encrypting payment data in transit with TLS 1.3 is a risk mitigation control that protects the confidentiality and integrity of data as it travels between the customer and the payment gateway. It reduces the likelihood of successful interception and unauthorized access, directly addressing the risk of data compromise during transmission.

Why this answer

Risk mitigation controls reduce the likelihood or impact of a risk. Tokenization and TLS encryption both directly reduce the risk of credit card data interception by making the data unusable or unreadable to attackers. Cyber insurance transfers risk, avoiding online payments avoids risk, and outsourcing shares risk; none of these directly mitigate the technical vulnerability.

Exam trap

The trap here is misclassifying risk transfer or avoidance as mitigation, especially when controls like insurance or outsourcing feel like active responses.

88
MCQeasy

An organization purchases cyber insurance to cover potential losses from data breaches. This is an example of:

A.Risk Avoidance
B.Risk Transfer
C.Risk Mitigation
D.Risk Acceptance
AnswerB

Cyber insurance shifts the financial consequence of a data breach to an insurer for a premium, which is risk transfer. The organisation retains the risk itself but transfers the potential loss, unlike avoidance, reduction or acceptance.

Why this answer

Purchasing cyber insurance transfers the financial risk of a data breach to the insurer, making it a classic example of risk transfer. In risk management, transfer shifts the impact of a loss to a third party (e.g., an insurance carrier) without eliminating the underlying threat or vulnerability. This aligns with the CRISC domain of Risk Response and Mitigation, where transfer is a distinct response strategy.

Exam trap

The trap here is that candidates confuse risk transfer with risk mitigation, thinking insurance reduces the likelihood of a breach, when in fact it only shifts the financial consequences.

How to eliminate wrong answers

Option A is wrong because risk avoidance would mean eliminating the activity that causes the risk (e.g., not storing any sensitive data), not insuring against it. Option C is wrong because risk mitigation involves implementing controls (e.g., encryption, firewalls) to reduce the likelihood or impact of a breach, not transferring financial liability. Option D is wrong because risk acceptance means formally acknowledging the risk and bearing the potential loss without purchasing insurance or implementing additional controls.

89
MCQhard

A multinational bank is subject to GDPR and local data protection laws. The risk practitioner is reviewing a risk treatment plan for a new customer analytics platform that will process personal data across three jurisdictions. The plan proposes to rely on the vendor's standard contractual clauses (SCCs) as the primary control for cross-border data transfers. Which factor is MOST important for the risk practitioner to evaluate when assessing the adequacy of this risk response?

A.Whether the vendor's SCCs have been updated to the latest regulatory version and whether a transfer impact assessment has been completed for each jurisdiction.
B.Whether the analytics platform uses encryption in transit and at rest for all personal data.
C.Whether the vendor has a SOC 2 Type II report covering the analytics platform's security controls.
D.Whether the vendor's data retention policy aligns with the bank's internal records management schedule.
AnswerA

SCCs are a legal transfer mechanism, but their adequacy depends on the current regulatory version and a jurisdiction-specific transfer impact assessment. The risk practitioner must verify that the clauses are valid and that local laws do not undermine them. This evaluation ensures the control actually mitigates the regulatory and legal risk of cross-border transfers, rather than merely appearing compliant on paper.

Why this answer

When SCCs are used as a cross-border transfer control, their adequacy depends on being current with regulatory requirements and being supported by a transfer impact assessment for each destination jurisdiction. The risk practitioner must evaluate legal validity and local law conflicts, not just technical security or retention practices. This ensures the risk response actually mitigates the regulatory risk of unlawful data transfers under GDPR and local laws.

Exam trap

The trap here is focusing on technical security controls like encryption or SOC 2 reports when the risk is the legal adequacy of the cross-border transfer mechanism.

90
MCQmedium

A risk assessment reveals that a legacy system has a high likelihood of failure. The system is critical and cannot be replaced immediately. The company decides to implement manual overrides and additional monitoring. This is an example of:

A.Risk Transfer
B.Risk Mitigation
C.Risk Acceptance
D.Risk Avoidance
AnswerB

Manual overrides and added monitoring reduce the likelihood or impact of the legacy system's failure while it remains in service, which is risk mitigation. The system cannot be replaced immediately, so avoidance and acceptance are ruled out; the controls lower the high likelihood identified in the assessment.

Why this answer

Implementing manual overrides and additional monitoring reduces the probability or impact of the legacy system failure without eliminating the risk entirely. This is the definition of risk mitigation, as it applies controls to lower the residual risk to an acceptable level while the system remains in operation.

Exam trap

The trap here is that candidates confuse 'risk mitigation' with 'risk acceptance' because the system is still running with known vulnerabilities, but the key differentiator is that active controls are being applied to reduce the risk, not merely acknowledged.

How to eliminate wrong answers

Option A is wrong because risk transfer would involve shifting the financial burden of failure to a third party (e.g., purchasing cyber insurance or outsourcing the system), not adding internal controls. Option C is wrong because risk acceptance means formally acknowledging the risk without taking any action to reduce it, which contradicts the decision to implement overrides and monitoring. Option D is wrong because risk avoidance would require removing the system or the activity causing the risk, such as decommissioning the legacy system entirely, which is explicitly stated as not immediately possible.

91
MCQeasy

After a risk assessment, a company decides to stop using a third-party service that has high residual risk. This is an example of:

A.Risk Mitigation
B.Risk Avoidance
C.Risk Transfer
D.Risk Acceptance
AnswerB

Risk avoidance eliminates the activity generating the risk entirely, so the high residual risk from the third-party service ceases to exist rather than being reduced, transferred or accepted. Discontinuing the service satisfies the stem's constraint of removing exposure, unlike mitigation which would retain the relationship while adding controls.

Why this answer

By discontinuing the use of the third-party service, the company eliminates the risk entirely rather than reducing or accepting it. This is the definition of risk avoidance, where the activity giving rise to the risk is ceased. The decision is based on the residual risk being too high to be acceptable or cost-effectively mitigated.

Exam trap

The trap here is that candidates confuse 'avoidance' with 'mitigation' because both involve action, but avoidance eliminates the risk source entirely, whereas mitigation reduces but does not remove the risk.

How to eliminate wrong answers

Option A is wrong because risk mitigation involves implementing controls to reduce the likelihood or impact of a risk, not stopping the activity entirely. Option C is wrong because risk transfer would involve shifting the risk to another party (e.g., through insurance or outsourcing), not ceasing the service. Option D is wrong because risk acceptance means formally acknowledging and tolerating the residual risk without taking further action, which is the opposite of stopping the service.

92
MCQhard

After implementing multiple controls, the residual risk for a new product launch is still slightly above the risk appetite. The risk manager decides to proceed with the launch and monitor the risks regularly. This is:

A.Risk Transfer
B.Risk Avoidance
C.Risk Acceptance
D.Risk Mitigation
AnswerC

Proceeding with a launch where residual risk exceeds appetite, while monitoring regularly, is deliberate risk acceptance. The organisation acknowledges the exposure and chooses to retain it rather than mitigate, transfer or avoid it, which defines acceptance as the risk response.

Why this answer

The risk manager's decision to proceed with the launch despite residual risk exceeding the risk appetite, while committing to regular monitoring, is the definition of risk acceptance. In IT risk management, this acknowledges that the remaining risk is tolerable for business objectives, and the monitoring plan ensures any escalation is detected early. This is not a passive decision but an active, documented acceptance of the residual risk level.

Exam trap

In the CRISC exam, the nuance is that risk acceptance is not inaction but a deliberate, documented decision to tolerate residual risk above appetite with ongoing monitoring, which candidates mistakenly confuse with risk mitigation or avoidance.

How to eliminate wrong answers

Option A is wrong because risk transfer would involve shifting the financial impact of the risk to a third party (e.g., cyber insurance or outsourcing), not proceeding with internal monitoring. Option B is wrong because risk avoidance would mean canceling or not launching the product to eliminate the risk entirely, which contradicts the decision to proceed. Option D is wrong because risk mitigation would require implementing additional controls to reduce the residual risk below the appetite, not accepting it above the threshold.

93
Multi-Selectmedium

Which THREE of the following are key components of an effective risk response plan?

Select 3 answers
A.Documented risk response strategy (e.g., avoid, mitigate, transfer, accept)
B.Detailed implementation timeline
C.Assigned ownership and accountability
D.Regulatory impact analysis
E.Resource allocation and budget
AnswersA, C, E

The chosen strategy is a fundamental part of the plan.

Why this answer

A documented risk response strategy (e.g., avoid, mitigate, transfer, accept) is a key component because it formally defines the chosen approach for addressing each identified risk. This documentation ensures that the response aligns with the organization's risk appetite and provides a clear directive for subsequent actions, such as implementing controls or transferring risk via insurance.

Exam trap

The trap here is that candidates confuse project management components (like timelines and detailed schedules) with the strategic, decision-oriented components of a risk response plan, leading them to select 'Detailed implementation timeline' instead of recognizing that ownership, strategy, and budget are the three pillars CRISC emphasizes.

94
MCQhard

A risk assessment identifies that a legacy system has a high risk of failure with no available vendor support. The organization decides to decommission the system and migrate to a modern platform. This is:

A.Risk Avoidance
B.Risk Transfer
C.Risk Mitigation
D.Risk Acceptance
AnswerA

Decommissioning the legacy system eliminates the risk entirely by removing the asset and its exposure, rather than transferring, mitigating or accepting it. Eliminating the activity that generates the risk is the defining characteristic of risk avoidance.

Why this answer

Decommissioning the legacy system and migrating to a modern platform eliminates the risk entirely by removing the vulnerable asset from the environment. This is the definition of risk avoidance, as the organization chooses not to engage with the risk at all rather than reducing or transferring it. The decision directly addresses the high risk of failure and lack of vendor support by removing the system from operation.

Exam trap

The trap here is that candidates often confuse risk avoidance with risk mitigation, mistakenly thinking that any proactive action (like migrating) is a form of mitigation, whereas avoidance specifically means ceasing the activity that generates the risk.

How to eliminate wrong answers

Option B is wrong because risk transfer would involve shifting the financial impact of failure to a third party (e.g., purchasing cyber insurance or outsourcing to a managed service provider), not removing the system. Option C is wrong because risk mitigation would involve implementing controls to reduce the likelihood or impact of failure (e.g., adding monitoring, applying patches, or isolating the system) while keeping it operational. Option D is wrong because risk acceptance means formally acknowledging the risk and its potential consequences without taking action, which contradicts the active decision to decommission and migrate.

← PreviousPage 2 of 2 · 94 questions total

Ready to test yourself?

Try a timed practice session using only Risk Response and Mitigation questions.