nerdexam
CompTIA

SY0-501 · Question #561

A company recently replaced its unsecure email server with a cloud-based email and collaboration solution that is managed and insured by a third party. Which of the following actions did the company…

The correct answer is A. Transference. When a company moves to a third-party managed and insured cloud service, it shifts financial and operational responsibility for associated risks to that external provider, which is the definition of risk transference.

Submitted by viktor_hu· Mar 4, 2026Security program management and oversight

Question

A company recently replaced its unsecure email server with a cloud-based email and collaboration solution that is managed and insured by a third party. Which of the following actions did the company take regarding risks related to its email and collaboration services?

Options

  • ATransference
  • BAcceptance
  • CMitigation
  • DDeterrence

How the community answered

(39 responses)
  • A
    72% (28)
  • B
    15% (6)
  • C
    8% (3)
  • D
    5% (2)

Why each option

When a company moves to a third-party managed and insured cloud service, it shifts financial and operational responsibility for associated risks to that external provider, which is the definition of risk transference.

ATransferenceCorrect

Risk transference involves shifting the financial or operational burden of a risk to another party, such as a third-party vendor or insurer. By adopting a cloud-based solution that is both managed and insured by a third party, the company has transferred responsibility for securing and guaranteeing the email service away from itself. The insurance component is a key indicator of transference, as it explicitly moves financial liability to an outside entity.

BAcceptance

Acceptance means the company acknowledges the risk and chooses to do nothing about it, which is not the case here since the company actively replaced its insecure server with a third-party solution.

CMitigation

Mitigation involves reducing the likelihood or impact of a risk through internal controls or improvements, but moving to a fully managed and insured third-party service transfers rather than internally reduces the risk.

DDeterrence

Deterrence involves discouraging threat actors from targeting the organization through warnings or consequences, which has no relevance to replacing an email server with a cloud-based managed service.

Concept tested: Risk management strategy: transference vs other responses

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/policy-compliance/risk-tolerance

Topics

#risk transference#cloud services#third-party risk#risk management

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice