nerdexam
(ISC)2

CGRC · Question #8

You are the project manager for GHY Project and are working to create a risk response for a negative risk. You and the project team have identified the risk that the project may not complete on…

The correct answer is C. Transference. Hiring an external writer to address the risk of not completing a user guide on time is an example of risk transference, as the responsibility and impact are shifted to a third party.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

You are the project manager for GHY Project and are working to create a risk response for a negative risk. You and the project team have identified the risk that the project may not complete on time, as required by the management, due to the creation of the user guide for the software you're creating. You have elected to hire an external writer in order to satisfy the requirements and to alleviate the risk event. What type of risk response have you elected to use in this instance? Response:

Options

  • ASharing
  • BAvoidance
  • CTransference
  • DExploiting

How the community answered

(14 responses)
  • A
    14% (2)
  • B
    7% (1)
  • C
    79% (11)

Why each option

Hiring an external writer to address the risk of not completing a user guide on time is an example of risk transference, as the responsibility and impact are shifted to a third party.

ASharing

Risk sharing involves allocating risk ownership to multiple parties, but the scenario describes outsourcing the entire activity and its associated risk to a single external entity.

BAvoidance

Risk avoidance involves eliminating the threat or its cause entirely, which is not the case here, as the user guide still needs to be created.

CTransferenceCorrect

Risk transference is a risk response strategy where the responsibility for managing a risk, and the impact if it occurs, is shifted to a third party. By hiring an external writer, the project transfers the risk of the user guide not being completed on time to that external party.

DExploiting

Risk exploiting is a positive risk response strategy aimed at increasing the probability or impact of an opportunity, which is irrelevant for a negative risk like delayed project completion.

Concept tested: Risk response strategies - transference

Source: https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/reference/nfa-security#risk-transfer

Topics

#Risk Management#Risk Response Strategies#Risk Transference#Negative Risk

Community Discussion

No community discussion yet for this question.

Full CGRC Practice