nerdexam
GIAC

GSLC · Question #408

You are the project manager of a Web development project. You want to get information about your competitors by hacking into their computers. You and the project team determine should the hacking…

The correct answer is B. Transference. Hiring a professional hacker to perform the attack transfers the risk and its consequences to a third party, which is the definition of risk transference.

Risk Management & Compliance

Question

You are the project manager of a Web development project. You want to get information about your competitors by hacking into their computers. You and the project team determine should the hacking attack not be performed anonymously, you will be traced. Hence, you hire a professional hacker to work on the project. This is an example of what type of risk response?

Options

  • AAcceptance
  • BTransference
  • CMitigation
  • DAvoidance

How the community answered

(29 responses)
  • B
    93% (27)
  • C
    3% (1)
  • D
    3% (1)

Why each option

Hiring a professional hacker to perform the attack transfers the risk and its consequences to a third party, which is the definition of risk transference.

AAcceptance

Risk acceptance means acknowledging the risk and choosing to take no action to address it, which is not the case here since a deliberate action - hiring someone - is taken.

BTransferenceCorrect

Risk transference involves shifting the financial or legal burden of a risk to another party, such as a third-party contractor, insurer, or vendor. By hiring a professional hacker, the project manager transfers the legal liability and exposure of the hacking activity away from the organization to the hired individual. This mirrors the concept used in outsourcing risky activities or purchasing insurance as a risk response strategy.

CMitigation

Risk mitigation involves reducing the probability or impact of a risk through preventive actions, whereas hiring a hacker does not reduce the risk itself but rather shifts responsibility.

DAvoidance

Risk avoidance means changing the project plan to eliminate the risk or its trigger entirely, such as deciding not to perform the hacking activity at all.

Concept tested: Risk transference as a project risk response strategy

Source: https://www.pmi.org/learning/library/risk-response-strategies-novel-approaches-7814

Topics

#risk transference#risk response strategies#third-party risk#project risk management

Community Discussion

No community discussion yet for this question.

Full GSLC Practice