CompTIA Security+ (SY0-701)Security Program Management and OversightEasy
A company decides that the risk of operating an outdated third-party payment plugin is too high due to known vulnerabilities and a lack of vendor patches. Rather than accept, mitigate, or transfer the risk, the company removes the plugin entirely and switches to a different payment processing method. Which risk response strategy does this represent?
- ARisk mitigation
- BRisk transference
- CRisk acceptance
- DRisk avoidance
Show answer & explanationAnswer & explanation
Correct answer: D. Risk avoidance
Risk avoidance means eliminating the activity or condition that creates the risk entirely, such as discontinuing use of a vulnerable component. Mitigation reduces risk while keeping the activity, transference shifts risk to a third party, and acceptance means proceeding despite the risk.
Why the other options are wrong
- A. Mitigation would keep the plugin but add compensating controls.
- B. Transference shifts the risk (e.g., via insurance or a vendor contract), not applicable here.
- C. Acceptance means continuing to use the plugin despite the risk.
Risk Avoidance
A risk response strategy that eliminates the risk by discontinuing the activity, process, or asset that creates it.
- Removes the risk source entirely, not just its impact
- Often used when mitigation costs exceed the value of the activity
- Contrasts with acceptance, mitigation, and transference
Memory trick: Avoid it, Accept it, Transfer it, Mitigate it — AATM your risk.