100-160 exam dumps

100-160 practice question 198 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 198

Select 2

A company has recently identified that its internal systems are vulnerable to ransomware attacks. As part of a broader risk management process, the company decides to implement regular data backups and employee cybersecurity training. Which risk management strategies are being applied in this scenario?

  1. A

    Risk avoidance

  2. B

    Risk mitigation

  3. C

    Risk transfer

  4. D

    Risk acceptance

  5. E

    Risk sharing

Show answer and explanation

Correct answers: B, D

Explanation

The company is taking a risk mitigation approach by reducing the potential impact of ransomware through backups and training. Additionally, the company acknowledges that the risk cannot be completely eliminated and therefore accepts it while taking proactive steps to manage the consequences. These strategies align with risk mitigation and risk acceptance in the context of risk management.

  • A. Incorrect.

    Risk avoidance involves completely eliminating the risk by choosing not to engage in the activity that causes the risk. In this scenario, the company is not avoiding the risk but addressing it through other means.

  • B. Correct.

    Risk mitigation involves reducing the likelihood or impact of a risk. Implementing regular data backups and employee cybersecurity training is aimed at decreasing the potential damage from ransomware attacks, which is a risk mitigation strategy.

  • C. Incorrect.

    Risk transfer involves shifting the responsibility of the risk to a third party, such as purchasing cyber insurance. This is not described in the scenario.

  • D. Correct.

    Risk acceptance involves acknowledging the risk and taking no further action beyond monitoring it. By implementing training and backups, the company is accepting the inherent risk of ransomware but preparing for potential impacts, which aligns with risk acceptance to some extent.

  • E. Incorrect.

    Risk sharing involves distributing the risk among multiple parties, often through partnerships or agreements. This is not applicable in this context.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam