SY0-701 exam dumps

SY0-701 practice question 179 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 179

Single answerRisk transference

A regional healthcare provider is moving a patient scheduling application to a third-party cloud platform. The security manager determines that outages or breaches affecting the hosted environment could create significant financial and legal exposure for the organization. The provider wants to reduce its direct financial impact if the cloud environment is compromised, without eliminating the service or reducing the underlying likelihood of an incident. Which action BEST represents risk transference?

  1. A

    Purchase a cyber liability insurance policy that covers incident response, legal costs, and breach-related losses

  2. B

    Implement additional web application firewall rules and endpoint detection agents for the application

  3. C

    Decommission the scheduling application and return to a manual paper-based process

  4. D

    Accept the risk because the cloud provider is responsible for securing all hosted workloads

Show answer and explanation

Correct answer: A

Explanation

Risk transference means shifting the financial or contractual burden of risk to another party, commonly through insurance, indemnification clauses, or certain outsourcing agreements. In this scenario, the key requirement is to reduce direct financial impact without stopping the activity and without lowering the probability of an incident. That makes cyber insurance the best answer. By contrast, implementing additional security controls is risk mitigation, shutting down the service is risk avoidance, and doing nothing is risk acceptance or misunderstanding. This aligns with common risk management guidance such as NIST SP 800-39, which distinguishes risk response strategies including acceptance, avoidance, mitigation, and transfer/transference. Candidates should also recognize that cloud services operate under a shared responsibility model; using a cloud provider does not automatically transfer all security risk.

  • A. Correct.

    Correct. Purchasing cyber liability insurance is a classic example of risk transference. The organization is shifting part of the financial impact of a security incident to a third party, typically an insurer. This does not prevent the incident from occurring, but it can reduce the organization's direct monetary loss after an event.

  • B. Incorrect.

    Incorrect. Adding WAF rules and EDR controls is risk mitigation, not risk transference. These controls are intended to reduce the likelihood or impact of an attack by improving protection and detection, rather than transferring the financial burden to another party.

  • C. Incorrect.

    Incorrect. Decommissioning the application is risk avoidance. The organization would be eliminating the activity that creates the risk, rather than transferring the financial consequences of that risk to another entity.

  • D. Incorrect.

    Incorrect. This reflects a misunderstanding of shared responsibility in cloud environments. While the cloud provider may secure parts of the infrastructure, the customer still retains responsibility for many aspects of security and compliance. Simply assuming the provider owns all risk is not risk transference and would be a poor security decision.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam