nerdexam
CompTIA

CAS-003 · Question #462

The finance department has started to use a new payment system that requires strict PII security restrictions on various network devices. The company decides to enforce the restrictions and…

The correct answer is D. Accept. NOTE: The marked correct answer is D (Accept), but this appears to be an error. The correct answer should be B (Mitigate). Risk mitigation means implementing security controls to reduce the likelihood or impact of a risk. When the company responds to PII security requirements…

Risk Management

Question

The finance department has started to use a new payment system that requires strict PII security restrictions on various network devices. The company decides to enforce the restrictions and configure all devices appropriately. Which of the following risk response strategies is being used?

Options

  • AAvoid
  • BMitigate
  • CTransfer
  • DAccept

How the community answered

(60 responses)
  • A
    3% (2)
  • B
    7% (4)
  • C
    2% (1)
  • D
    88% (53)

Explanation

NOTE: The marked correct answer is D (Accept), but this appears to be an error. The correct answer should be B (Mitigate). Risk mitigation means implementing security controls to reduce the likelihood or impact of a risk. When the company responds to PII security requirements by actively configuring all network devices with the appropriate restrictions, it is taking concrete action to reduce risk exposure-that is the definition of mitigation. Risk acceptance means acknowledging a risk and choosing to proceed without implementing additional controls. Since the company is not ignoring the risk but instead deploying security configurations to address it, the strategy is unambiguously mitigation.

Topics

#risk response strategies#PII security#PCI DSS#compliance

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice