SY0-501 · Question #489
A Chief Information Officer (CIO) has decided it is not cost effective to implement safeguards against a known vulnerability. Which of the following risk responses does this BEST describe?
The correct answer is D. Acceptance. The CIO's decision to not implement safeguards against a known vulnerability due to cost-effectiveness best describes risk acceptance.
Question
A Chief Information Officer (CIO) has decided it is not cost effective to implement safeguards against a known vulnerability. Which of the following risk responses does this BEST describe?
Options
- ATransference
- BAvoidance
- CMitigation
- DAcceptance
How the community answered
(35 responses)- A11% (4)
- B3% (1)
- C3% (1)
- D83% (29)
Why each option
The CIO's decision to not implement safeguards against a known vulnerability due to cost-effectiveness best describes risk acceptance.
Transference involves shifting the risk to a third party, for example, through insurance or outsourcing, which is not what the CIO is doing.
Avoidance means eliminating the risk entirely by stopping the activity that causes it, which is not reflected by the CIO's decision to forgo safeguards for an existing vulnerability.
Mitigation involves implementing controls or safeguards to reduce the likelihood or impact of a risk, which is the opposite of the CIO's decision not to implement safeguards.
Risk acceptance occurs when an organization acknowledges a risk but decides not to take any action to reduce it, often because the cost of mitigation outweighs the potential impact or the risk is deemed tolerable. In this scenario, the CIO has performed a cost-benefit analysis and consciously chosen not to invest in safeguards, thereby accepting the inherent risk.
Concept tested: Risk management strategies and responses
Source: https://learn.microsoft.com/en-us/training/modules/describe-risk-management-concepts/4-describe-risk-treatment-and-response
Topics
Community Discussion
No community discussion yet for this question.