SY0-501 · Question #561
A company recently replaced its unsecure email server with a cloud-based email and collaboration solution that is managed and insured by a third party. Which of the following actions did the company…
The correct answer is A. Transference. When a company moves to a third-party managed and insured cloud service, it shifts financial and operational responsibility for associated risks to that external provider, which is the definition of risk transference.
Question
A company recently replaced its unsecure email server with a cloud-based email and collaboration solution that is managed and insured by a third party. Which of the following actions did the company take regarding risks related to its email and collaboration services?
Options
- ATransference
- BAcceptance
- CMitigation
- DDeterrence
How the community answered
(39 responses)- A72% (28)
- B15% (6)
- C8% (3)
- D5% (2)
Why each option
When a company moves to a third-party managed and insured cloud service, it shifts financial and operational responsibility for associated risks to that external provider, which is the definition of risk transference.
Risk transference involves shifting the financial or operational burden of a risk to another party, such as a third-party vendor or insurer. By adopting a cloud-based solution that is both managed and insured by a third party, the company has transferred responsibility for securing and guaranteeing the email service away from itself. The insurance component is a key indicator of transference, as it explicitly moves financial liability to an outside entity.
Acceptance means the company acknowledges the risk and chooses to do nothing about it, which is not the case here since the company actively replaced its insecure server with a third-party solution.
Mitigation involves reducing the likelihood or impact of a risk through internal controls or improvements, but moving to a fully managed and insured third-party service transfers rather than internally reduces the risk.
Deterrence involves discouraging threat actors from targeting the organization through warnings or consequences, which has no relevance to replacing an email server with a cloud-based managed service.
Concept tested: Risk management strategy: transference vs other responses
Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/policy-compliance/risk-tolerance
Topics
Community Discussion
No community discussion yet for this question.