Soru

Zorluk: OrtaRisk Identification, Assessment, and Response Strategies

An enterprise security team is addressing risks associated with a critical legacy operational technology (OT) monitoring console that cannot be updated or patched without voiding vendor support compliance. To manage this liability, the organization purchases a third-party cybersecurity insurance policy covering unauthorized access incidents and deploys an isolated, read-only out-of-band network monitoring tap to detect suspicious network traffic without interrupting operations. Which of the following risk response strategies are demonstrated in this scenario? (Select TWO.)

  1. Risk TransferenceCevap
  2. Risk MitigationCevap
  3. C
    Risk Avoidance
  4. D
    Risk Acceptance

Cevap

Risk Transference and Risk Mitigation
Purchasing a cyber insurance policy transfers financial liability for security breaches to a third-party insurer (Risk Transference). Implementing out-of-band traffic monitoring reduces the risk profile by providing early threat detection without disrupting legacy system stability (Risk Mitigation).

Adım Adım Çözüm

1
Analyze the financial protection strategy described in the scenario.
Obtaining a cybersecurity insurance policy shifts the financial liability of a breach to an external insurer.
Risk transference involves delegating or shifting risk liability to a third party.
2
Analyze the technical security control implemented in the scenario.
Installing an out-of-band read-only tap introduces detective capabilities that lower the risk footprint of the unpatchable asset.
Risk mitigation involves taking action to reduce the probability or impact of a threat.

Anahtar Kavram

Risk Response Strategies
Bu soruyu puanla