nerdexam
CompTIA

CAS-003 · Question #527

A financial institution's information security officer is working with the risk management officer to determine what to do with the institution's residual risk after all security controls have been…

The correct answer is A. Transfer the risk. Residual risk is the risk that remains after all security controls have been implemented. With a very low risk tolerance, simply accepting residual risk (D) is inappropriate. Mitigating further (C) is not viable since all controls are already in place. Avoidance (B) would…

Risk Management

Question

A financial institution's information security officer is working with the risk management officer to determine what to do with the institution's residual risk after all security controls have been implemented. Considering the institution's very low risk tolerance, which of the following strategies would be BEST?

Options

  • ATransfer the risk.
  • BAvoid the risk
  • CMitigate the risk.
  • DAccept the risk.

How the community answered

(25 responses)
  • A
    76% (19)
  • B
    4% (1)
  • C
    16% (4)
  • D
    4% (1)

Explanation

Residual risk is the risk that remains after all security controls have been implemented. With a very low risk tolerance, simply accepting residual risk (D) is inappropriate. Mitigating further (C) is not viable since all controls are already in place. Avoidance (B) would require ceasing the business activity entirely, which is usually not practical. Transferring the risk - typically through cyber insurance or contractual agreements - shifts the financial liability of a potential loss to a third party, satisfying a low risk tolerance without halting operations. This is the standard strategy when controls have been exhausted and accepting residual exposure is not acceptable.

Topics

#residual risk#risk transfer#risk tolerance#risk treatment strategies

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice