ISC2 Certified in Cybersecurity (CC)Security PrinciplesEasy

A cybersecurity team is performing a comprehensive assessment of an organization's network infrastructure. They discover that several legacy servers are running outdated operating systems with known vulnerabilities for which no patches are available. Management decides to isolate these servers on a separate, heavily restricted network segment and implement an intrusion detection system (IDS) to monitor all traffic to and from them. Which risk treatment strategy is the organization primarily employing in this scenario?

  1. ARisk Mitigation
  2. BRisk Transference
  3. CRisk Acceptance
  4. DRisk Avoidance
Show answer & explanation

Correct answer: A. Risk Mitigation

Risk mitigation involves taking steps to reduce the likelihood or impact of a risk. Isolating vulnerable servers and implementing an IDS are actions taken to lessen the potential harm from the identified vulnerabilities.

Why the other options are wrong

  • B. Risk transference involves shifting the risk to a third party, such as through insurance, which is not described.
  • C. Risk acceptance means acknowledging a risk and taking no action to reduce it, which is not the case here.
  • D. Risk avoidance means eliminating the activity that causes the risk, which is not feasible for legacy servers that are still required.

Risk Mitigation

The process of taking actions to reduce the likelihood or impact of a risk.

  • Involves implementing controls and safeguards.
  • Aims to lessen potential harm.
  • Common strategy in cybersecurity.

Memory trick: Always MITIGATE risks to make them LESS of a problem.

More Security Principles questions