312-50V13 · Question #11
Suppose your company has just passed a security risk assessment exercise. The results display that the risk of the breach in the main company application is 50%. Security staff has taken some…
The correct answer is A. Accept the risk. When a risk's probability is below the established acceptable threshold after mitigation, the most business-profitable decision is to accept the remaining risk.
Question
Options
- AAccept the risk
- BIntroduce more controls to bring risk to 0%
- CMitigate the risk
- DAvoid the risk
How the community answered
(48 responses)- A79% (38)
- B2% (1)
- C6% (3)
- D13% (6)
Why each option
When a risk's probability is below the established acceptable threshold after mitigation, the most business-profitable decision is to accept the remaining risk.
The risk has been reduced to 10%, which is below the company's established risk threshold of 20%. Since the risk is now within acceptable limits and further mitigation to 0% is often unfeasible or too costly, accepting the remaining risk is the most cost-effective decision for project continuation and business profit.
It is generally impossible or economically prohibitive to bring any risk down to 0%, as security controls always have associated costs and limitations.
Mitigating the risk has already been successfully performed, reducing it to an acceptable level; the question asks for the best decision *now* based on the acceptable residual risk.
Avoiding the risk would mean discontinuing the project or application, which contradicts the goal of 'successful continuation with the most business profit' given the risk is now acceptable.
Concept tested: Risk management strategies (Accept, Mitigate, Avoid, Transfer)
Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/secure/security-governance-risk-compliance-strategy
Topics
Community Discussion
No community discussion yet for this question.