Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementEasy
A small e-commerce startup is conducting its first cybersecurity risk assessment. They have identified that a data breach could lead to significant financial losses and reputational damage. However, due to limited resources, they decide to focus their initial efforts on implementing basic security controls like strong passwords and multi-factor authentication. Which risk management strategy are they primarily employing?
- ARisk Mitigation
- BRisk Acceptance
- CRisk Avoidance
- DRisk Transfer
Show answer & explanationAnswer & explanation
Correct answer: A. Risk Mitigation
By implementing basic security controls like strong passwords and multi-factor authentication, the startup is taking actions to reduce the likelihood or impact of a data breach, which is the definition of risk mitigation.
Why the other options are wrong
- B. Risk acceptance means choosing to take no action to reduce the risk.
- C. Risk avoidance means eliminating the activity that causes the risk.
- D. Risk transfer involves shifting the risk to another party, typically through insurance or outsourcing.
Risk Mitigation
The process of taking steps to reduce the likelihood or impact of an identified risk. This often involves implementing security controls or countermeasures.
- Aims to reduce likelihood or impact.
- Involves implementing controls.
- A common risk response strategy.
Memory trick: AART: Avoid, Accept, Reduce, Transfer.