nerdexam
CompTIA

CAS-002 · Question #353

The Chief Information Security Officer (CISO) at a company knows that many users store business documents on public cloud-based storage; and realizes this is a risk to the company. In response, the…

The correct answer is C. Mitigate. Implementing mandatory training reduces the likelihood or impact of employees misusing cloud storage, which is a risk mitigation strategy rather than elimination, transfer, or acceptance.

Integration of Computing, Communications and Business Disciplines

Question

The Chief Information Security Officer (CISO) at a company knows that many users store business documents on public cloud-based storage; and realizes this is a risk to the company. In response, the CISO implements a mandatory training course in which all employees are instructed on the proper use of cloud-based storage. Which of the following risk strategies did the CISO implement?

Options

  • AAvoid
  • BAccept
  • CMitigate
  • DTransfer

How the community answered

(56 responses)
  • A
    4% (2)
  • B
    7% (4)
  • C
    88% (49)
  • D
    2% (1)

Why each option

Implementing mandatory training reduces the likelihood or impact of employees misusing cloud storage, which is a risk mitigation strategy rather than elimination, transfer, or acceptance.

AAvoid

Risk avoidance would require prohibiting cloud-based storage entirely, eliminating the activity that creates the risk, which the CISO did not do.

BAccept

Risk acceptance means acknowledging the risk and taking no action to reduce it; implementing training is an active control, not passive acceptance.

CMitigateCorrect

Risk mitigation involves taking actions to reduce the probability or impact of a risk, and mandatory security awareness training directly addresses the human behavior that causes the risk of improper cloud storage use. The risk is not eliminated (employees could still misuse cloud storage) and not transferred to another party, so it qualifies specifically as mitigation. Training is a recognized administrative control that reduces residual risk without avoiding the use of cloud storage entirely.

DTransfer

Risk transfer shifts the financial or operational burden of a risk to a third party, such as through cyber insurance or a contract clause, which training does not accomplish.

Concept tested: Risk management strategy - mitigation via administrative controls

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#risk management#risk mitigation#cloud storage#security awareness training

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice