nerdexam
CompTIA

CAS-001 · Question #333

activities have uncovered systemic security issues in the flagship product of Company average estimates indicating a cost of $1.6millon. Which of the following approaches should the risk manager of…

The correct answer is D. Avoid the risk. The question describes systemic (pervasive, deeply embedded) security issues in the flagship product. When vulnerabilities are systemic rather than isolated, mitigating or transferring them may be insufficient and extremely costly. With an estimated remediation cost of $1.6…

Integration of Computing, Communications and Business Disciplines

Question

activities have uncovered systemic security issues in the flagship product of Company average estimates indicating a cost of $1.6millon. Which of the following approaches should the risk manager of Company XYZ recommend?

Options

  • ATransfer the risk
  • BAccept the risk
  • CMitigate the risk
  • DAvoid the risk

How the community answered

(48 responses)
  • A
    4% (2)
  • B
    8% (4)
  • C
    17% (8)
  • D
    71% (34)

Explanation

The question describes systemic (pervasive, deeply embedded) security issues in the flagship product. When vulnerabilities are systemic rather than isolated, mitigating or transferring them may be insufficient and extremely costly. With an estimated remediation cost of $1.6 million and fundamental flaws in the product, the risk manager should recommend avoiding the risk - meaning eliminating the source of the risk entirely (e.g., discontinuing the vulnerable product, redesigning from scratch, or ceasing the activity that creates the exposure). Risk avoidance is appropriate when the risk cannot be adequately controlled and the cost/impact is unacceptably high.

Topics

#risk avoidance#risk treatment#risk management#product security risk

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice