A healthcare organization's security team identified a critical remote code execution vulnerability in a legacy diagnostic server. Because replacing or updating the server would temporarily disrupt essential patient care operations, the Chief Information Security Officer (CISO) approves placing the server on an isolated microsegmented subnet, restricting inbound network traffic using strict firewall rules, and deploying specialized host monitoring to reduce the likelihood of exploitation. Which risk response strategy did the organization primarily execute?
- Risk MitigationCevap
- BRisk Avoidance
- CRisk Transference
- DRisk Acceptance
Cevap
Risk Mitigation
Risk mitigation (also called risk reduction) involves implementing technical, administrative, or physical security controls to diminish the likelihood and potential impact of a vulnerability exploitation. Placing the server on an isolated subnet and enforcing strict firewall rules reduces the attack surface while allowing the medical organization to continue essential patient care operations.
Adım Adım Çözüm
Anahtar Kavram
Selecting and classifying risk response strategies (Mitigation, Avoidance, Transference, Acceptance)
Tahmini Süre:1m 0s