A financial technology company is establishing risk management controls for its public customer feedback portal. To manage risks associated with potential web application threats and security breaches, the CISO approves purchasing a specialized cyber insurance policy while also deploying multi-factor authentication (MFA) and API rate limiting on the portal. Which of the following risk response strategies are being directly implemented by the organization in this scenario? (Select TWO.)
- Risk transference, by purchasing an insurance policy to shift financial liability to a third partyCevap
- Risk mitigation, by implementing technical controls to reduce the likelihood and impact of exploitationCevap
- CRisk avoidance, by completely disabling and decommissioning the web portal to eliminate threat exposure
- DRisk acceptance, by choosing to retain the full impact of potential breaches without taking defensive action
Cevap
The correct risk response strategies implemented in this scenario are risk transference (purchasing cyber insurance to shift financial risk) and risk mitigation (deploying MFA and rate limiting to reduce likelihood and impact).
Purchasing cyber insurance shifts potential financial loss to an external entity, representing risk transference. Implementing security controls like multi-factor authentication and rate limiting lowers the probability and impact of security incidents, representing risk mitigation.
Adım Adım Çözüm
Anahtar Kavram
Risk Response Strategies (Transference vs. Mitigation vs. Avoidance vs. Acceptance)
Tahmini Süre:1m 30s