An organization is evaluating its risk management procedures to align with standard risk response strategies. Which of the following actions correctly represent valid risk response strategies? (Select TWO.)
- Purchasing a commercial cyber insurance policy to cover financial losses resulting from data breaches.Answer
- BDeploying a deception honeypot to act as an inline security control for filtering malicious incoming traffic.
- Decommissioning a vulnerable legacy service entirely to eliminate the risk of remote exploitation.Answer
- DCalculating Annual Loss Expectancy by adding the Single Loss Expectancy directly to the Annual Rate of Occurrence.
Answer
The actions representing valid risk response strategies are purchasing a cyber insurance policy (risk transference) and decommissioning a vulnerable legacy service (risk avoidance).
Purchasing cyber insurance shifts the financial burden of an attack to an insurance provider, which is the definition of risk transference. Decommissioning a vulnerable legacy application removes the threat vector completely, which is the definition of risk avoidance.
Step-by-Step Solution
Key Concept
Risk Response Strategies (Avoidance, Transference, Mitigation, Acceptance)