Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security

A company's risk register shows that a phishing attack on its payroll system has a high likelihood and a moderate impact. Management buys cyber insurance to cover the financial loss while taking no other step. Which risk treatment option is this?

This is risk transfer. By purchasing cyber insurance, the company shifts the financial consequence of a possible phishing loss to the insurer, without removing the activity or adding controls. Avoidance would stop the activity, and mitigation would reduce likelihood or impact through safeguards.

  1. ARisk avoidance
  2. BRisk transferCorrect
  3. CRisk mitigation
  4. DRisk acceptance

Explanation

Buying insurance shifts the financial consequence of the loss to an insurer, which is risk transfer. Avoidance would mean dropping the payroll system or activity altogether. Mitigation would reduce likelihood or impact through controls such as training or filters, which management did not adopt here.

Did you get it right without looking?

One question tells you little. A timed set on Cyber Security shows your real accuracy, how long you take and where you lose marks.

More Cyber Security questions