Posted by: Pdfprep
Post Date: March 31, 2021
A security analyst is providing a risk assessment for a medical device that will be installed on the corporate network. During the assessment, the analyst discovers the device has an embedded operating system that will be at the end of its life in two years. Due to the criticality of the device, the security committee makes a risk-based policy decision to review and enforce the vendor upgrade before the end of life is reached.
Which of the following risk actions has the security committee taken?
A . Risk exception
B . Risk avoidance
C . Risk tolerance
D . Risk acceptance
Answer: D
Leave a Reply