Question

Difficulty: EasyRisk Identification, Assessment, and Response Strategies

An organization discovers that an old standalone web server running a critical legacy service contains severe unpatchable vulnerabilities. To eliminate the threat of an external remote compromise entirely, the security team decides to shut down and permanently decommission the server without replacing its function. Which risk response strategy has the organization applied?

  1. Risk avoidanceAnswer
  2. B
    Risk mitigation
  3. C
    Risk transfer
  4. D
    Risk acceptance

Answer

Risk avoidance is the strategy applied when an organization completely eliminates exposure to a risk by discontinuing the associated activity or removing the risky asset entirely.
Risk avoidance entails altering plans or operational behavior to entirely remove the risk exposure. In this scenario, permanently shutting down and decommissioning the vulnerable legacy system prevents any possibility of that system being compromised.

Step-by-Step Solution

1
Analyze the action taken in the scenario
The organization permanently decommissions and shuts down the vulnerable server entirely.
Identifying the operational action determines whether risk is reduced, shared, tolerated, or completely eliminated.
2
Evaluate the risk outcome
The risk of remote exploitation for this asset becomes zero because the asset no longer exists on the network.
Total elimination of risk by refraining from or ceasing the risky activity corresponds precisely to risk avoidance.

Key Concept

Risk Response Strategies: Avoidance vs. Mitigation vs. Transfer vs. Acceptance
Rate this question