Soru

Zorluk: OrtaRisk Identification, Assessment, and Response Strategies

An enterprise discovers that a specialized legacy API used for international currency conversion cannot be secured against recent protocol vulnerabilities. Because the revenue generated through this API is minimal compared to the potential liability of a security breach, the executive team decides to disable and remove the API entirely from production, halting all processing of those transactions. Which of the following risk response strategies did the organization implement?

  1. Risk avoidanceCevap
  2. B
    Risk mitigation
  3. C
    Risk transference
  4. D
    Risk acceptance

Cevap

Risk avoidance
Risk avoidance involves taking proactive measures to eliminate exposure to a threat by entirely removing the underlying asset, vulnerable application, or business activity that generates the risk.

Adım Adım Çözüm

1
Analyze the organizational decision described in the scenario.
The organization chose to disable and decommission the vulnerable API, completely ceasing the high-risk transaction activity.
Evaluating the specific action taken establishes whether the risk was altered, shared, tolerated, or eliminated.
2
Map the observed action to official risk management response definitions.
Discontinuing a business process or eliminating the asset that introduces the exposure constitutes Risk Avoidance.
Risk avoidance is defined as completely removing the vulnerability vector or terminating the activity causing the risk.

Anahtar Kavram

Risk Response Strategies (Avoidance vs. Mitigation vs. Transference vs. Acceptance)
Bu soruyu puanla