CAS-003 · Question #462
The finance department has started to use a new payment system that requires strict PII security restrictions on various network devices. The company decides to enforce the restrictions and…
The correct answer is D. Accept. NOTE: The marked correct answer is D (Accept), but this appears to be an error. The correct answer should be B (Mitigate). Risk mitigation means implementing security controls to reduce the likelihood or impact of a risk. When the company responds to PII security requirements…
Question
The finance department has started to use a new payment system that requires strict PII security restrictions on various network devices. The company decides to enforce the restrictions and configure all devices appropriately. Which of the following risk response strategies is being used?
Options
- AAvoid
- BMitigate
- CTransfer
- DAccept
How the community answered
(60 responses)- A3% (2)
- B7% (4)
- C2% (1)
- D88% (53)
Explanation
NOTE: The marked correct answer is D (Accept), but this appears to be an error. The correct answer should be B (Mitigate). Risk mitigation means implementing security controls to reduce the likelihood or impact of a risk. When the company responds to PII security requirements by actively configuring all network devices with the appropriate restrictions, it is taking concrete action to reduce risk exposure-that is the definition of mitigation. Risk acceptance means acknowledging a risk and choosing to proceed without implementing additional controls. Since the company is not ignoring the risk but instead deploying security configurations to address it, the strategy is unambiguously mitigation.
Topics
Community Discussion
No community discussion yet for this question.