nerdexam
CompTIA

CAS-001 · Question #29

The Chief Executive Officer (CEO) of a corporation purchased the latest mobile device and wants to connect it to the internal network. The Chief Information Security Officer (CISO) was told to…

The correct answer is A. Mitigate and Transfer. When a required risk cannot be eliminated because a stakeholder demands access, the appropriate strategy is to implement controls that reduce the risk (mitigate) while shifting residual liability to a third party (transfer).

Research and Analysis

Question

The Chief Executive Officer (CEO) of a corporation purchased the latest mobile device and wants to connect it to the internal network. The Chief Information Security Officer (CISO) was told to research and recommend how to secure this device. Which of the following should be implemented, keeping in mind that the CEO has stated that this access is required?

Options

  • AMitigate and Transfer
  • BAccept and Transfer
  • CTransfer and Avoid
  • DAvoid and Mitigate

How the community answered

(43 responses)
  • A
    74% (32)
  • B
    5% (2)
  • C
    7% (3)
  • D
    14% (6)

Why each option

When a required risk cannot be eliminated because a stakeholder demands access, the appropriate strategy is to implement controls that reduce the risk (mitigate) while shifting residual liability to a third party (transfer).

AMitigate and TransferCorrect

Because the CEO has explicitly stated that mobile device access to the network is required, avoiding the risk is not an option; therefore the CISO should mitigate the risk by implementing security controls such as device encryption, MDM enrollment, and strong authentication, and transfer remaining residual risk through mechanisms such as cyber liability insurance or contractual agreements.

BAccept and Transfer

Accepting the risk means acknowledging it without implementing controls, which is inappropriate for a known security risk involving sensitive corporate data on a mobile device.

CTransfer and Avoid

Transfer alone without mitigation leaves the organization exposed to the full risk, and avoidance contradicts the CEO's explicit requirement that access be maintained.

DAvoid and Mitigate

Avoidance requires not using the device or network connection, which directly contradicts the CEO's stated requirement that access is mandatory.

Concept tested: Risk treatment strategies - mitigate and transfer

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#risk response#risk treatment#mobile security#risk management

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice