Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementHard
During a vulnerability assessment, an analyst discovers a critical vulnerability in a legacy system that cannot be patched due to vendor discontinuation and core application dependencies. Disabling the vulnerable service would break essential business functions. The organization has decided to isolate the system on a separate network segment with strict access controls and monitor it continuously for suspicious activity. Which risk response strategy does this describe?
- ARisk Acceptance
- BRisk Avoidance
- CRisk Transfer
- DRisk Mitigation
Show answer & explanationAnswer & explanation
Correct answer: D. Risk Mitigation
Risk mitigation involves taking actions to reduce the likelihood or impact of a risk. In this scenario, isolating the system and implementing strict monitoring are measures designed to reduce the risk of the vulnerability being exploited, even if the vulnerability itself cannot be eliminated.
Why the other options are wrong
- A. Risk acceptance means doing nothing about the risk, which is contradicted by the active measures taken to isolate and monitor the system.
- B. Risk avoidance would mean removing the system or the vulnerable service entirely, which is not possible here as it's essential.
- C. Risk transfer involves shifting the risk to another party, such as through insurance, which is not what's happening.
Risk Mitigation
The process of implementing controls or measures to reduce the likelihood or impact of a risk event, rather than eliminating the risk entirely.
- Aims to reduce, not eliminate, risk.
- Involves implementing security controls or compensating measures.
- Often used when risk avoidance or transfer is not feasible.
Memory trick: Avoid, Mitigate, Transfer, Accept.