nerdexam
CompTIA

CAS-002 · Question #35

A wholesaler has decided to increase revenue streams by selling direct to the public through an on-line system. Initially this will be run as a short term trial and if profitable, will be expanded…

The correct answer is C. Transfer the initial risks by outsourcing payment processing to a third party service provider. Both identified risks - lack of in-house expertise and the compliance burden of PCI DSS - are directly addressed by outsourcing payment processing to a qualified third-party provider (e.g., Stripe, PayPal, Braintree). This is a risk transfer strategy: the third party assumes…

Integration of Computing, Communications and Business Disciplines

Question

A wholesaler has decided to increase revenue streams by selling direct to the public through an on-line system. Initially this will be run as a short term trial and if profitable, will be expanded and form part of the day to day business. The risk manager has raised two main business risks for the initial trial: 1. IT staff has no experience with establishing and managing secure on- line credit card processing. 2. An internal credit card processing system will expose the business to additional compliance requirements. Which of the following is the BEST risk mitigation strategy?

Options

  • ATransfer the risks to another internal department, who have more resources to accept the
  • BAccept the risks and log acceptance in the risk register.
  • CTransfer the initial risks by outsourcing payment processing to a third party service provider.
  • DMitigate the risks by hiring additional IT staff with the appropriate experience and

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    16% (6)
  • C
    74% (28)
  • D
    8% (3)

Explanation

Both identified risks - lack of in-house expertise and the compliance burden of PCI DSS - are directly addressed by outsourcing payment processing to a qualified third-party provider (e.g., Stripe, PayPal, Braintree). This is a risk transfer strategy: the third party assumes responsibility for PCI DSS compliance and brings the necessary expertise. This is especially appropriate for a short-term trial where investing in staff training (Option D) or building internal infrastructure would not be cost-justified. Accepting the risks (Option B) is inappropriate given the financial and legal exposure, and transferring to another internal department (Option A) does not eliminate the risks, only relocates them.

Topics

#risk transfer#PCI compliance#third-party outsourcing#payment processing

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice