Soru

Zorluk: KolayRisk Identification, Assessment, and Response Strategies

An enterprise security team is reviewing options for managing identified operational risks within their IT infrastructure. Which of the following represent recognized risk response strategies? (Select TWO.)

  1. Risk mitigation, which implements security controls to reduce the likelihood or impact of a threat.Cevap
  2. B
    Risk calculation, which multiplies Single Loss Expectancy (SLE) by Annual Rate of Occurrence (ARO).
  3. Risk transference, which shifts financial liability or exposure to an external third party.Cevap
  4. D
    Control misclassification, which categorizes defensive mechanisms under incorrect functional types.

Cevap

Risk mitigation and risk transference are recognized risk response strategies.
The correct options state risk mitigation and risk transference. Mitigation focuses on lowering the likelihood or impact of a risk through internal controls, while transference reallocates financial impact to another organization, such as an insurance underwriter or service provider.

Adım Adım Çözüm

1
Identify the primary risk management phase targeted by the question.
The scenario requires identifying risk response (treatment) options rather than assessment metrics or auditing errors.
Risk response selection takes place after risks have been identified and analyzed.
2
Evaluate the choices against established risk response options (Mitigation, Transference, Avoidance, Acceptance).
Mitigation and Transference directly match established risk response strategies.
Mitigation actively reduces risk exposure using controls, while Transference shifts financial consequences to a third party.

Anahtar Kavram

Risk Response Strategies
Bu soruyu puanla