An enterprise security team is reviewing options for managing identified operational risks within their IT infrastructure. Which of the following represent recognized risk response strategies? (Select TWO.)
- Risk mitigation, which implements security controls to reduce the likelihood or impact of a threat.Answer
- BRisk calculation, which multiplies Single Loss Expectancy (SLE) by Annual Rate of Occurrence (ARO).
- Risk transference, which shifts financial liability or exposure to an external third party.Answer
- DControl misclassification, which categorizes defensive mechanisms under incorrect functional types.
Answer
Risk mitigation and risk transference are recognized risk response strategies.
The correct options state risk mitigation and risk transference. Mitigation focuses on lowering the likelihood or impact of a risk through internal controls, while transference reallocates financial impact to another organization, such as an insurance underwriter or service provider.
Step-by-Step Solution
Key Concept
Risk Response Strategies