nerdexam
EC-Council

312-50V11 · Question #705

A medium-sized healthcare IT business decides to implement a risk management strategy. Which of the following is NOT one of the five basic responses to risk?

The correct answer is B. Delegate. The five standard responses to risk are Accept, Avoid, Mitigate, Transfer, and Reject/Ignore - Delegate is not a recognized risk response category.

Information Security and Ethical Hacking Fundamentals

Question

A medium-sized healthcare IT business decides to implement a risk management strategy. Which of the following is NOT one of the five basic responses to risk?

Options

  • AAccept
  • BDelegate
  • CMitigate
  • DAvoid

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    95% (18)

Why each option

The five standard responses to risk are Accept, Avoid, Mitigate, Transfer, and Reject/Ignore - Delegate is not a recognized risk response category.

AAccept

Accept is a valid and commonly used risk response where the organization acknowledges a risk and decides to tolerate it, often because the cost of mitigation exceeds the potential impact.

BDelegateCorrect

Delegate is not one of the five basic risk responses in standard risk management frameworks such as NIST SP 800-30 or ISACA's CRISC model. Delegation describes an organizational or managerial action of assigning responsibility, not a strategy for handling risk itself. The legitimate five responses are: Accept (acknowledge and tolerate the risk), Avoid (eliminate the risk-causing activity), Mitigate (reduce likelihood or impact), Transfer (shift risk to a third party such as via insurance), and sometimes Reject/Ignore.

CMitigate

Mitigate is a standard risk response that involves implementing controls to reduce the probability or impact of a risk to an acceptable level.

DAvoid

Avoid is a valid risk response where the organization eliminates the activity or condition that gives rise to the risk entirely.

Concept tested: Five standard risk management response strategies

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#risk management#risk response#security governance#risk strategies

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice