nerdexam
CompTIA

CAS-003 · Question #26

Management is reviewing the results of a recent risk assessment of the organization's policies and procedures. During the risk assessment it is determined that procedures associated with background…

The correct answer is A. Transfer. The organization responded to the identified risk by outsourcing background checks to a third-party provider. This is the classic definition of risk transfer (also called risk sharing) - the operational responsibility and liability for performing background checks is shifted to…

Risk Management

Question

Management is reviewing the results of a recent risk assessment of the organization's policies and procedures. During the risk assessment it is determined that procedures associated with background checks have not been effectively implemented. In response to this risk, the organization elects to revise policies and procedures related to background checks and use a third-party to perform background checks on all new employees. Which of the following risk management strategies has the organization employed?

Options

  • ATransfer
  • BMitigate
  • CAccept
  • DAvoid
  • EReject

How the community answered

(42 responses)
  • A
    90% (38)
  • B
    2% (1)
  • C
    5% (2)
  • D
    2% (1)

Explanation

The organization responded to the identified risk by outsourcing background checks to a third-party provider. This is the classic definition of risk transfer (also called risk sharing) - the operational responsibility and liability for performing background checks is shifted to an external entity. The third party now assumes accountability for properly executing that function. While revising internal policies and procedures has elements of mitigation, the defining action described is moving the function to an outside party. Risk mitigation would involve implementing internal controls to improve the background check process. Risk avoidance would mean stopping the activity that creates the risk (e.g., stopping all hiring). Risk acceptance would mean acknowledging the gap and doing nothing. There is no formally recognized 'Reject' strategy in standard risk management frameworks.

Topics

#risk transfer#background checks#third-party vendor#risk management strategies

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice