Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementHard
An organization is conducting a comprehensive risk assessment. They have identified several high-risk vulnerabilities in their legacy systems. Due to budget constraints and the end-of-life status of these systems, a decision is made to leave them operational but isolated on a separate network segment with strict access controls, rather than replacing them entirely. This strategy is primarily an example of which risk mitigation technique?
- ARisk Acceptance
- BRisk Reduction
- CRisk Transfer
- DRisk Avoidance
Show answer & explanationAnswer & explanation
Correct answer: B. Risk Reduction
By isolating the systems and implementing strict access controls, the organization is actively taking steps to reduce the likelihood and/or impact of a successful exploit, even without replacing the systems. This is a form of risk reduction (or mitigation) rather than outright acceptance.
Why the other options are wrong
- A. Risk acceptance would mean leaving the systems operational without implementing additional controls.
- C. Risk transfer would involve shifting the risk to another party, which is not happening here.
- D. Risk avoidance would mean decommissioning the legacy systems entirely.
Risk Reduction
A risk response strategy that involves implementing controls or countermeasures to decrease the likelihood of a risk event occurring, or to lessen its impact if it does occur.
- Most common risk response strategy.
- Includes technical, administrative, and physical controls.
- Aims to lower the overall risk level to an acceptable threshold.
Memory trick: Reduce, Isolate, Control: The three ways to lessen risk.