A security analyst is recommending controls to address vulnerabilities discovered during a recent internal security review. Which of the following security actions represent examples of Risk Mitigation? (Select TWO.)
- Applying security updates and software patches to eliminate known operating system vulnerabilities.Cevap
- BPurchasing a comprehensive cyber liability insurance policy to cover potential breach financial losses.
- Installing network intrusion prevention systems (IPS) to detect and block malicious traffic targeting internal servers.Cevap
- DDisabling and taking offline an unsupported web application to completely eliminate its associated attack surface.
Cevap
Risk Mitigation involves taking specific actions or deploying controls to reduce the probability or impact of a threat. Applying software patches and installing an Intrusion Prevention System (IPS) are both mitigation techniques.
Risk mitigation involves implementing controls and safeguards to lower the likelihood or impact of a security event while continuing the operational activity. Applying software patches closes known security holes, reducing vulnerability likelihood. Deploying an Intrusion Prevention System (IPS) actively blocks malicious activity, reducing risk impact and probability.
Adım Adım Çözüm
Anahtar Kavram
Risk Response Strategies (Mitigation vs. Transfer vs. Avoidance)
Tahmini Süre:45s