nerdexam
CompTIA

CAS-005 · Question #307

Company A acquired Company B. During an audit, a security engineer found Company B's environment was inadequately patched. In response, Company A placed a firewall between the two environments until…

The correct answer is D. Mitigate. Company A acquired Company B, found B's environment inadequately patched, and placed a firewall between the two networks until B's infrastructure was integrated.

Submitted by rohit_dlh· Mar 6, 2026Governance, Risk, and Compliance

Question

Company A acquired Company B. During an audit, a security engineer found Company B's environment was inadequately patched. In response, Company A placed a firewall between the two environments until Company B's infrastructure could be integrated into Company A's security program. Which of the following risk-handling techniques was used?

Options

  • AAccept
  • BAvoid
  • CTransfer
  • DMitigate

How the community answered

(24 responses)
  • B
    4% (1)
  • C
    4% (1)
  • D
    92% (22)

Why each option

Company A acquired Company B, found B's environment inadequately patched, and placed a firewall between the two networks until B's infrastructure was integrated.

AAccept

Accepting risk involves acknowledging it without taking action to reduce it, which contradicts the active measure of placing a firewall.

BAvoid

Avoiding risk means eliminating the activity causing the risk, which would imply not acquiring Company B or immediately decommissioning its systems.

CTransfer

Transferring risk involves shifting the financial burden or responsibility to another party, such as through insurance, which is not what was done by implementing a firewall.

DMitigateCorrect

Mitigate is the risk-handling technique used when an organization implements controls or countermeasures to reduce the likelihood or impact of a risk. Placing a firewall between the two environments directly reduces the risk of Company B's inadequately patched systems affecting Company A's network by controlling access, thereby mitigating the risk.

Concept tested: Risk management strategies

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/top-security-best-practices#risk-management-strategies

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice