SY0-701 Question 180
Single answerRisk transferenceA healthcare software company is preparing to launch a new patient portal that will store limited protected health information (PHI). The security manager identifies a residual risk that a data breach could still result in significant legal costs, customer notification expenses, and third-party claims even after implementing encryption, MFA, logging, and regular vulnerability scanning. The executive team wants to reduce the company's financial exposure without eliminating the project or handing day-to-day security operations to another provider. Which action BEST represents risk transference?
- A
Purchase a cyber liability insurance policy to cover breach-related costs
- B
Delay the portal launch until all identified risks are eliminated
- C
Accept the residual risk because compensating controls are already in place
- D
Outsource the entire patient portal environment to a managed service provider
Show answer and explanation
Correct answer: A
Explanation
Risk transference means shifting the financial or contractual impact of a risk to another entity, commonly through insurance, indemnification clauses, or other contractual mechanisms. In Security+, the most straightforward example is purchasing cyber insurance to offset breach-related financial losses. By contrast, avoidance means not engaging in the risky activity, mitigation means implementing controls to reduce likelihood or impact, and acceptance means retaining the residual risk. This aligns with common risk management practices described by NIST, including the concept of responding to risk through acceptance, avoidance, mitigation, or sharing/transference depending on organizational objectives and residual exposure.
- A. Correct.
Correct. Purchasing cyber liability insurance is a classic example of risk transference because the organization shifts part of the financial impact of a potential incident to a third party, the insurer. This does not remove the need for security controls, but it transfers some of the monetary consequences such as legal fees, notification costs, and certain liability claims.
- B. Incorrect.
Incorrect. Delaying the launch to avoid the risk is an example of risk avoidance, not transference. In avoidance, the organization changes plans or stops the activity entirely to eliminate exposure from that activity.
- C. Incorrect.
Incorrect. Accepting the residual risk means the organization acknowledges the remaining exposure and chooses to retain it. This is common when the cost of further mitigation exceeds the benefit, but it does not transfer the risk to another party.
- D. Incorrect.
Incorrect. Outsourcing operations can sometimes transfer certain operational responsibilities, but it does not automatically transfer the organization's risk, accountability, or liability. In this scenario, the requirement specifically says the company does not want to hand day-to-day operations to another provider. Also, using an MSP is more closely related to mitigation or partial sharing of responsibility, not the clearest example of risk transference for financial exposure.