nerdexam
EC-Council

312-50V9 · Question #27

Which of the following is considered an acceptable option when managing a risk?

The correct answer is C. Mitigate the risk. Risk management defines four accepted responses to risk: mitigate, accept, avoid, and transfer. Only mitigation is among the valid options listed.

Introduction to Ethical Hacking

Question

Which of the following is considered an acceptable option when managing a risk?

Options

  • AReject the risk.
  • BDeny the risk.
  • CMitigate the risk.
  • DInitiate the risk.

How the community answered

(62 responses)
  • A
    5% (3)
  • B
    2% (1)
  • C
    92% (57)
  • D
    2% (1)

Why each option

Risk management defines four accepted responses to risk: mitigate, accept, avoid, and transfer. Only mitigation is among the valid options listed.

AReject the risk.

Reject is not a recognized risk management response; risks cannot simply be declared non-existent or refused.

BDeny the risk.

Deny is not a formal risk treatment option in any standard risk management framework.

CMitigate the risk.Correct

Mitigation is one of the four standard risk management responses recognized in frameworks like NIST and CompTIA Security+. It involves implementing controls to reduce the likelihood or impact of a risk to an acceptable level. The other valid responses - accept, avoid, and transfer - are not offered as choices here.

DInitiate the risk.

Risks are identified and analyzed, not initiated; initiating a risk is not a management response.

Concept tested: Standard risk management response options

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#risk management#risk mitigation#risk treatment#security policy

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice