nerdexam
CompTIA

CAS-002 · Question #51

A Chief Information Security Officer (CISO) has been trying to eliminate some IT security risks for several months. These risks are not high profile but still exist. Furthermore, many of these risks…

The correct answer is C. Accept the risks. When risks have already been partially mitigated with innovative solutions but the remaining budget is insufficient to fully address them, the appropriate strategy is to accept the risks. Risk acceptance (C) is a deliberate business decision to acknowledge a risk and tolerate…

Integration of Computing, Communications and Business Disciplines

Question

A Chief Information Security Officer (CISO) has been trying to eliminate some IT security risks for several months. These risks are not high profile but still exist. Furthermore, many of these risks have been mitigated with innovative solutions. However, at this point in time, the budget is insufficient to deal with the risks. Which of the following risk strategies should be used?

Options

  • ATransfer the risks
  • BAvoid the risks
  • CAccept the risks
  • DMitigate the risks

How the community answered

(34 responses)
  • A
    6% (2)
  • C
    91% (31)
  • D
    3% (1)

Explanation

When risks have already been partially mitigated with innovative solutions but the remaining budget is insufficient to fully address them, the appropriate strategy is to accept the risks. Risk acceptance (C) is a deliberate business decision to acknowledge a risk and tolerate it - typically documented and approved by management - when the cost of further mitigation exceeds the benefit or resources are unavailable. 'Transfer' (A) would mean shifting liability (e.g., via insurance), which isn't indicated here. 'Avoid' (B) means eliminating the activity that causes the risk, which may not be feasible. 'Mitigate' (D) is already being done but is budget-constrained, making further mitigation impossible at this time.

Topics

#risk acceptance#risk strategy#budget constraints#risk management

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice