Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementEasy

A cybersecurity analyst is evaluating a critical web server that hosts the company's main e-commerce platform. They have identified a high-severity vulnerability that could lead to a complete compromise of customer data. The cost to implement a patch immediately is estimated at $5,000. However, if exploited, the estimated financial loss due to data breach fines, reputational damage, and recovery efforts is $2,000,000. The analyst recommends immediately patching the vulnerability. Which risk management strategy is the analyst primarily recommending?

  1. ARisk Avoidance
  2. BRisk Acceptance
  3. CRisk Mitigation
  4. DRisk Transfer
Show answer & explanation

Correct answer: C. Risk Mitigation

The analyst is recommending an action (patching) to reduce the likelihood or impact of the identified vulnerability. This active step to lessen the potential harm is known as risk mitigation.

Why the other options are wrong

  • A. Risk avoidance would mean shutting down the e-commerce platform or not using the web server at all, which is not the recommended action.
  • B. Risk acceptance involves acknowledging the risk and taking no action to reduce it, which is not what the analyst is recommending.
  • D. Risk transfer involves shifting the financial burden of a risk to another party, typically through insurance, which is not what patching does.

Risk Mitigation

Risk mitigation is the process of taking steps to reduce the likelihood or impact of a identified risk.

  • Involves implementing controls or countermeasures.
  • Aims to lower the overall risk level.
  • Can include technical, administrative, or physical controls.

Memory trick: Mitigate the impact, lessen the fright, make the system safe and bright.

More Risk Management questions