100-160 Question 196
Single answerA cybersecurity team is tasked with implementing a risk management strategy for an organization's IT infrastructure. During a recent assessment, they identified a potential risk where unauthorized users could exploit a vulnerability to gain access to sensitive customer data. Which of the following actions best demonstrates the team applying risk management principles?
- A
Patching the identified vulnerability to reduce the likelihood of exploitation
- B
Ignoring the vulnerability because it has not yet been exploited
- C
Implementing additional firewalls and intrusion detection systems to monitor for unauthorized access attempts
- D
Documenting the risk and accepting it without taking further action
Show answer and explanation
Correct answer: A
Explanation
Risk management involves identifying, assessing, and mitigating risks to reduce their impact or likelihood. In this scenario, patching the vulnerability directly addresses the identified risk and demonstrates an effective mitigation strategy, making it the best option.
- A. Correct.
Patching the identified vulnerability is a direct approach to mitigating the risk, aligning with risk management principles that aim to reduce either the likelihood or impact of a threat.
- B. Incorrect.
Ignoring the vulnerability is not a valid approach to risk management, as it leaves the organization exposed to potential threats.
- C. Incorrect.
While implementing firewalls and intrusion detection systems can help monitor for threats, it is not the most effective action for directly addressing the identified vulnerability.
- D. Incorrect.
Documenting the risk and accepting it without action may be appropriate in certain low-impact scenarios, but it is not suitable for a critical risk involving sensitive customer data.