Free CompTIA CySA+ CS0-003 Practice Question

Your organization has identified a security vulnerability in an internally developed application. After performing a risk assessment, it is determined that the cost of remediation exceeds the potential impact of the vulnerability being exploited. Additionally, there is no immediate threat or known exploit for this vulnerability. What is the MOST appropriate risk management response in this scenario?

  • Formally accept the risk and monitor for changes in the threat landscape.

  • Transfer the risk by outsourcing the application component to a third-party vendor.

  • Schedule the patch to be included in the next release cycle without additional review.

  • Patch the vulnerability immediately regardless of the remediation costs.

This question's topic:
CompTIA CySA+ CS0-003 / 
Vulnerability Management
Your Score:

Check or uncheck an objective to set which questions you will receive.