100-160 Question 200
Single answerAn organization is assessing its risk management strategy after a recent security audit identified multiple vulnerabilities. Which of the following actions best represents the 'risk mitigation' approach in risk management?
- A
Implementing a firewall to prevent unauthorized access to the network.
- B
Accepting the possibility of a minor data breach due to the low likelihood of occurrence.
- C
Shifting liability for potential data breaches to a third-party vendor through a contract.
- D
Deciding to shut down a high-risk application permanently to eliminate potential threats.
Show answer and explanation
Correct answer: A
Explanation
Risk mitigation involves taking proactive measures to reduce the likelihood or impact of a threat. Implementing a firewall is a clear example of risk mitigation because it directly addresses the risk by adding a layer of protection. The other options represent different strategies in the risk management process (acceptance, transfer, or avoidance), but they do not align with the definition of mitigation.
- A. Correct.
Implementing a firewall to prevent unauthorized access to the network is an example of 'risk mitigation,' as it actively reduces the likelihood or impact of a risk through protective measures.
- B. Incorrect.
Accepting the possibility of a minor data breach represents 'risk acceptance,' where the organization chooses to tolerate the risk without taking specific action to reduce it.
- C. Incorrect.
Shifting liability for potential data breaches to a third-party vendor is an example of 'risk transfer,' where the organization transfers the risk to another party.
- D. Incorrect.
Shutting down a high-risk application permanently is an example of 'risk avoidance,' as it involves eliminating the source of the risk entirely.