nerdexam
(ISC)2

CSSLP · Question #277

A part of a project deals with the hardware work. As a project manager, you have decided to hire a company to deal with all hardware work on the project. Which type of risk response is this?

The correct answer is C. Transference. Hiring an external company to manage specific project work, like hardware, is a risk response strategy that shifts the responsibility and associated risk to a third party.

Secure Software Supply Chain

Question

A part of a project deals with the hardware work. As a project manager, you have decided to hire a company to deal with all hardware work on the project. Which type of risk response is this?

Options

  • AExploit
  • BMitigation
  • CTransference
  • DAvoidance

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    84% (31)
  • D
    8% (3)

Why each option

Hiring an external company to manage specific project work, like hardware, is a risk response strategy that shifts the responsibility and associated risk to a third party.

AExploit

Exploit is a risk response strategy for positive risks (opportunities) to ensure the opportunity is realized, not for handling a negative risk by shifting it.

BMitigation

Mitigation involves taking action to reduce the probability or impact of a risk, not shifting the responsibility entirely.

CTransferenceCorrect

Transference is a risk response strategy where the responsibility for a risk and its impact is shifted to a third party, often through outsourcing or insurance. By hiring a company to deal with hardware work, the project manager transfers the risk associated with that work to the external company.

DAvoidance

Avoidance involves eliminating the threat by removing the cause, such as changing the project plan to bypass the risky activity, which is not what hiring a company does.

Concept tested: Project risk response strategies - Transference

Source: https://www.pmi.org/pmbok-guide-standards/foundational/pmbok/risk-management/risk-response-planning

Topics

#Risk Management#Risk Transference#Supply Chain Security#Third-Party Risk

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice