100-160 Question 202
Single answerA small business has discovered a vulnerability in their web application that allows unauthorized users to bypass authentication and access sensitive customer data. The business owner decides to implement multi-factor authentication (MFA) as a way to address this issue. How should this decision be categorized in the risk management process?
- A
Risk Avoidance
- B
Risk Transfer
- C
Risk Mitigation
- D
Risk Acceptance
Show answer and explanation
Correct answer: C
Explanation
Risk Mitigation is a key part of the risk management process where measures are taken to reduce the likelihood or impact of a risk. In this scenario, the business owner is addressing the vulnerability by implementing MFA, which reduces the likelihood of unauthorized access to sensitive data. This clearly categorizes the action as Risk Mitigation.
- A. Incorrect.
Risk Avoidance involves eliminating the activity that introduces the risk entirely. Implementing MFA does not remove the web application or the associated risk, so this is incorrect.
- B. Incorrect.
Risk Transfer involves shifting the risk to another party, such as through insurance or outsourcing. Implementing MFA does not transfer the risk, so this is incorrect.
- C. Correct.
Risk Mitigation involves taking steps to reduce the likelihood or impact of a risk. Implementing MFA reduces the likelihood of unauthorized access by adding an additional security layer, making this the correct choice.
- D. Incorrect.
Risk Acceptance involves knowingly accepting the risk without taking action. Since the business owner is actively implementing MFA to address the risk, this is incorrect.