nerdexam
CompTIA

CLO-002 · Question #603

A business analyst is drafting a risk response for the following action item: Inherited security control that has no immediate or foreseeable corrective action plan Given this action item, which of…

The correct answer is B. Acceptance. Acceptance is the appropriate risk response when a security control or risk cannot be immediately or foreseeably corrected, and no action is taken to mitigate or avoid it. In this case, the organization acknowledges the risk associated with the inherited security control and…

Cloud Security and Compliance

Question

A business analyst is drafting a risk response for the following action item:

Inherited security control that has no immediate or foreseeable corrective action plan Given this action item, which of the following is the appropriate risk response?

Options

  • ATransference
  • BAcceptance
  • CMitigation
  • DAvoidance

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    85% (29)
  • C
    6% (2)
  • D
    3% (1)

Explanation

Acceptance is the appropriate risk response when a security control or risk cannot be immediately or foreseeably corrected, and no action is taken to mitigate or avoid it. In this case, the organization acknowledges the risk associated with the inherited security control and accepts it, possibly due to limitations in resources or other factors. This response is common when the risk is deemed low or manageable in the short term.

Topics

#risk acceptance#inherited controls#risk response#risk management

Community Discussion

No community discussion yet for this question.

Full CLO-002 Practice