Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementHard
A government agency is performing a risk assessment for a new system that will store classified information. They identify a critical vulnerability that could lead to unauthorized access. Due to the sensitive nature of the data, the agency decides not to deploy the system until the vulnerability is fully remediated, even if it delays the project significantly. Which risk response strategy is being employed?
- ARisk Transfer
- BRisk Mitigation
- CRisk Acceptance
- DRisk Avoidance
Show answer & explanationAnswer & explanation
Correct answer: D. Risk Avoidance
By deciding not to deploy the system until the critical vulnerability is fully remediated, the agency is essentially avoiding the risk of unauthorized access to classified information by not engaging in the risky activity (deploying the vulnerable system). This is a form of risk avoidance.
Why the other options are wrong
- A. Risk transfer would involve shifting the risk to another entity, which is not happening here.
- B. Risk mitigation would involve deploying the system but with additional controls to reduce the vulnerability's impact or likelihood.
- C. Risk acceptance would mean deploying the system despite the known vulnerability.
Risk Avoidance
A risk management strategy that involves eliminating the risk by deciding not to engage in the activity or process that carries the risk. It is often used for high-impact, high-likelihood risks.
- Eliminates the risk entirely.
- Achieved by not performing the risky activity.
- Often results in lost opportunities.
Memory trick: AART: Avoid, Accept, Reduce, Transfer.