Question

Difficulty: MediumRisk Identification, Assessment, and Response Strategies

A financial technology company is establishing risk management controls for its public customer feedback portal. To manage risks associated with potential web application threats and security breaches, the CISO approves purchasing a specialized cyber insurance policy while also deploying multi-factor authentication (MFA) and API rate limiting on the portal. Which of the following risk response strategies are being directly implemented by the organization in this scenario? (Select TWO.)

  1. Risk transference, by purchasing an insurance policy to shift financial liability to a third partyAnswer
  2. Risk mitigation, by implementing technical controls to reduce the likelihood and impact of exploitationAnswer
  3. C
    Risk avoidance, by completely disabling and decommissioning the web portal to eliminate threat exposure
  4. D
    Risk acceptance, by choosing to retain the full impact of potential breaches without taking defensive action

Answer

The correct risk response strategies implemented in this scenario are risk transference (purchasing cyber insurance to shift financial risk) and risk mitigation (deploying MFA and rate limiting to reduce likelihood and impact).
Purchasing cyber insurance shifts potential financial loss to an external entity, representing risk transference. Implementing security controls like multi-factor authentication and rate limiting lowers the probability and impact of security incidents, representing risk mitigation.

Step-by-Step Solution

1
Analyze the action of purchasing a specialized cyber insurance policy.
Identified as Risk Transference.
Cyber insurance passes the financial consequences of a loss event to a third-party insurer.
2
Analyze the action of deploying multi-factor authentication (MFA) and API rate limiting.
Identified as Risk Mitigation.
Implementing security controls reduces the vulnerability exposure, thereby lowering the probability or impact of an attack.
3
Evaluate the remaining options against the scenario context.
Risk avoidance and risk acceptance are ruled out.
The organization neither decommissioned the portal (avoidance) nor chose to leave the exposure untreated (acceptance).

Key Concept

Risk Response Strategies (Transference vs. Mitigation vs. Avoidance vs. Acceptance)
Estimated Time:1m 30s
Rate this question