An organization relies on a legacy payment processing gateway that cannot be immediately upgraded due to vendor dependencies. A recent assessment identified multiple unpatched vulnerabilities in the gateway. To manage the associated exposure, the security team implements microsegmentation and deploys an inline web application firewall (WAF) to block exploit attempts, while the executive leadership team purchases a comprehensive cyber liability insurance policy to cover potential financial losses. Which of the following risk response strategies are implemented in this scenario? (Select TWO.)
- Risk mitigationAnswer
- Risk transferenceAnswer
- CRisk avoidance
- DRisk acceptance
Answer
The organization demonstrates risk mitigation by deploying technical security controls (microsegmentation and WAF) and risk transference by purchasing cyber liability insurance.
Risk mitigation is illustrated by deploying technical controls (microsegmentation and a web application firewall) to minimize vulnerability exposure. Risk transference is illustrated by securing a cyber liability insurance policy to pass monetary risk to an insurer.
Step-by-Step Solution
Key Concept
Risk Response Strategies