CLO-002 · Question #594
A business analyst is drafting a risk response for the following action item: Apply vulnerability ID 15281 by disabling SSL 3.0 on all systems. Given this action item, which of the following is the…
The correct answer is C. Mitigation. Mitigation is the appropriate risk response in this scenario because the action item involves addressing a vulnerability (SSL 3.0) by disabling it on all systems. The goal of this action is to reduce or minimize the risk associated with SSL 3.0, which is considered insecure…
Question
A business analyst is drafting a risk response for the following action item:
Apply vulnerability ID 15281 by disabling SSL 3.0 on all systems. Given this action item, which of the following is the appropriate risk response?
Options
- AAcceptance
- BTransference
- CMitigation
- DAvoidance
How the community answered
(44 responses)- A7% (3)
- B2% (1)
- C77% (34)
- D14% (6)
Explanation
Mitigation is the appropriate risk response in this scenario because the action item involves addressing a vulnerability (SSL 3.0) by disabling it on all systems. The goal of this action is to reduce or minimize the risk associated with SSL 3.0, which is considered insecure. Mitigation strategies aim to reduce the likelihood or impact of a risk, and disabling SSL 3.0 is a step toward improving security and reducing vulnerability.
Topics
Community Discussion
No community discussion yet for this question.