Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementHard

An organization is conducting a comprehensive risk assessment. They have identified several high-risk vulnerabilities in their legacy systems. Due to budget constraints and the end-of-life status of these systems, a decision is made to leave them operational but isolated on a separate network segment with strict access controls, rather than replacing them entirely. This strategy is primarily an example of which risk mitigation technique?

  1. ARisk Acceptance
  2. BRisk Reduction
  3. CRisk Transfer
  4. DRisk Avoidance
Show answer & explanation

Correct answer: B. Risk Reduction

By isolating the systems and implementing strict access controls, the organization is actively taking steps to reduce the likelihood and/or impact of a successful exploit, even without replacing the systems. This is a form of risk reduction (or mitigation) rather than outright acceptance.

Why the other options are wrong

  • A. Risk acceptance would mean leaving the systems operational without implementing additional controls.
  • C. Risk transfer would involve shifting the risk to another party, which is not happening here.
  • D. Risk avoidance would mean decommissioning the legacy systems entirely.

Risk Reduction

A risk response strategy that involves implementing controls or countermeasures to decrease the likelihood of a risk event occurring, or to lessen its impact if it does occur.

  • Most common risk response strategy.
  • Includes technical, administrative, and physical controls.
  • Aims to lower the overall risk level to an acceptable threshold.

Memory trick: Reduce, Isolate, Control: The three ways to lessen risk.

More Risk Management questions