Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam SY0-601 topic 1 question 407 discussion

Actual exam question from CompTIA's SY0-601
Question #: 407
Topic #: 1
[All SY0-601 Questions]

Which of the following scenarios BEST describes a risk reduction technique?

  • A. A security control objective cannot be met through a technical change, so the company purchases insurance and is no longer concerned about losses from data breaches.
  • B. A security control objective cannot be met through a technical change, so the company implements a policy to train users on a more secure method of operation.
  • C. A security control objective cannot be met through a technical change, so the company performs regular audits to determine if violations have occurred.
  • D. A security control objective cannot be met through a technical change, so the Chief Information Officer decides to sign off on the risk.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Ranaer
Highly Voted 1 year, 3 months ago
Selected Answer: B
A is transference. B is mitigation. C is detection. D is acceptance. The only answer reducing risk is B.
upvoted 19 times
LePecador
9 months, 2 weeks ago
Risk types: acceptance, avoidance, transferance, mitigation Control types: preventive, detective, corrective, derrent, compensative, physical According to the CompTIA guide, but the provided answer is correct B) because is mitigating (reducing) the risk by implementing a policy
upvoted 1 times
...
...
JT4
Highly Voted 6 months, 3 weeks ago
Just passed the exam with a score of 800 on 10/28/23. About 90% of the questions are from here. This question is on the exam.
upvoted 6 times
...
irtaza909
Most Recent 3 months, 3 weeks ago
Why it can not be c as regular audits will also help to reduce the risk?
upvoted 1 times
Mehe323
1 week, 5 days ago
It doesn't reduce the risk, the violations may have already occurred.
upvoted 1 times
...
...
gho5tface
9 months ago
Selected Answer: C
Going against the majority here...
upvoted 1 times
...
Bro111
10 months, 2 weeks ago
A is transference. B is avoidance. C is detection so mitigation. D is acceptance.
upvoted 2 times
je123
9 months, 1 week ago
B. is NOT avoidance. Nevertheless, B is a better risk reduction/mitigation technique compared to C.
upvoted 1 times
je123
9 months, 1 week ago
B is a better risk reduction/mitigation technique compared to C, because training is a preventive control, while C. is primarily a detective and subsequently corrective control. Prevention is the best form of Control.
upvoted 1 times
...
...
...
ApplebeesWaiter1122
11 months, 1 week ago
Selected Answer: B
In this scenario, the company recognizes that a technical change alone cannot effectively address the security control objective. Instead, they opt to implement a policy to train users on a more secure method of operation. By providing proper training and education to users, the company aims to reduce the risk associated with the control objective that cannot be met through technical means. This approach focuses on enhancing user awareness, knowledge, and behavior to mitigate potential security risks and improve overall security posture.
upvoted 3 times
...
SophyQueenCR82
1 year, 1 month ago
"A security control objective cannot be met through a technical change, so the company implements a policy to train users on a more secure method of operation." Risk reduction techniques are designed to lower the probability or impact of identified risks. Option B describes a risk reduction technique through the implementation of a policy to train users on a more secure method of operation, thereby reducing the probability of security incidents caused by user error.
upvoted 1 times
...
sdc939
1 year, 3 months ago
Selected Answer: B
B. A security control objective cannot be met through a technical change, so the company implements a policy to train users on a more secure method of operation.
upvoted 1 times
...
Jibz18
1 year, 3 months ago
Selected Answer: B
A security control objective cannot be met through a technical change, so the company implements a policy to train users on a more secure method of operation.
upvoted 1 times
...
hsdj
1 year, 3 months ago
Selected Answer: B
considering B
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...