An enterprise logistics company maintains a legacy asset-tracking application running on an unpatchable operating system. Completely replacing the application would cost $1.5 million and cause severe operational downtime. To address the threat of potential exploitation, the security team deploys an inline intrusion prevention system (IPS) and isolates the host within a dedicated virtual local area network (VLAN) guarded by strict firewall rules. Which of the following risk response strategies did the organization execute?
- Risk mitigationAnswer
- BRisk avoidance
- CRisk transfer
- DRisk acceptance
Answer
Risk mitigation
Risk mitigation (also known as risk reduction) involves implementing administrative, physical, or technical security controls to diminish the likelihood or impact of a risk. Installing an intrusion prevention system (IPS) and configuring network microsegmentation actively reduce the probability of exploitation without discontinuing the legacy server.
Step-by-Step Solution
Key Concept
Risk Response Strategies
Estimated Time:1m 15s