Soru

Zorluk: KolayRisk Identification, Assessment, and Response Strategies

A security analyst is recommending controls to address vulnerabilities discovered during a recent internal security review. Which of the following security actions represent examples of Risk Mitigation? (Select TWO.)

  1. Applying security updates and software patches to eliminate known operating system vulnerabilities.Cevap
  2. B
    Purchasing a comprehensive cyber liability insurance policy to cover potential breach financial losses.
  3. Installing network intrusion prevention systems (IPS) to detect and block malicious traffic targeting internal servers.Cevap
  4. D
    Disabling and taking offline an unsupported web application to completely eliminate its associated attack surface.

Cevap

Risk Mitigation involves taking specific actions or deploying controls to reduce the probability or impact of a threat. Applying software patches and installing an Intrusion Prevention System (IPS) are both mitigation techniques.
Risk mitigation involves implementing controls and safeguards to lower the likelihood or impact of a security event while continuing the operational activity. Applying software patches closes known security holes, reducing vulnerability likelihood. Deploying an Intrusion Prevention System (IPS) actively blocks malicious activity, reducing risk impact and probability.

Adım Adım Çözüm

1
Define Risk Mitigation
Identify that mitigation focuses on reducing risk likelihood or impact via controls and safeguards.
Risk mitigation aims to lessen the overall risk score without necessarily eliminating the underlying activity or transferring responsibility.
2
Evaluate option actions against risk response definitions
Patching systems reduces vulnerability exposure (Mitigation). Deploying an IPS blocks network attacks (Mitigation). Buying insurance shifts financial liability (Transfer). Decommissioning systems removes the risk source completely (Avoidance).
Categorizing each action clarifies which responses alter risk exposure directly through control implementation.

Anahtar Kavram

Risk Response Strategies (Mitigation vs. Transfer vs. Avoidance)
Tahmini Süre:45s
Bu soruyu puanla