ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 149 - SY0-701 discussion

Report
Export

Which of the following risk management strategies should an enterprise adopt first if a legacy application is critical to business operations and there are preventative controls that are not yet implemented?

A.
Mitigate
Answers
A.
Mitigate
B.
Accept
Answers
B.
Accept
C.
Transfer
Answers
C.
Transfer
D.
Avoid
Answers
D.
Avoid
Suggested answer: A

Explanation:

Mitigate is the risk management strategy that involves reducing the likelihood or impact of a risk. If a legacy application is critical to business operations and there are preventative controls that are not yet implemented, the enterprise should adopt the mitigate strategy first to address the existing vulnerabilities and gaps in the application. This could involve applying patches, updates, or configuration changes to the application, or adding additional layers of security controls around the application. Accept, transfer, and avoid are other risk management strategies, but they are not the best options for this scenario. Accept means acknowledging the risk and accepting the consequences without taking any action. Transfer means shifting the risk to a third party, such as an insurance company or a vendor. Avoid means eliminating the risk by removing the source or changing the process.These strategies may not be feasible or desirable for a legacy application that is critical to business operations and has no preventative controls in place.Reference:CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, page 1221; A Risk-Based Framework for Legacy System Migration and Deprecation2

asked 02/10/2024
M.G.Georgantzis QUALCO
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first