What Is the First Risk Management Strategy for a Critical Legacy Application?
Which of the following risk management strategies should an enterprise adopt first if a legacy application is critical to business operations and there are preventative controls that are not yet implemented?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests whether you recognize that critical business applications require risk reduction through implemented controls, making mitigation the appropriate first step over accepting, transferring, or avoiding.
For a legacy application critical to operations with missing preventative controls, the first risk management strategy should be mitigation, as it reduces risk to an acceptable level without disrupting business. Community consensus supports this view, with all votes selecting 'Mitigate'.
Choosing 'Accept' is the most common mistake, as some may think critical systems have inherent risks that must be accepted, but missing preventative controls mean the risk is too high to accept without action.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Mitigation is the correct first strategy because the legacy application is critical to business operations, meaning you cannot simply avoid it, and missing preventative controls mean the current risk is unacceptable. Mitigation involves implementing safeguards such as patching, adding compensating controls, or enhancing monitoring to reduce the risk to a manageable level. As noted in a comment, 'Mitigation would involve applying these controls to enhance security and reduce risk exposure.' Thus, mitigation is the immediate, proactive response.
Why the Other Options Are Wrong
'Accept' is wrong because accepting the risk without implementing any controls is only appropriate when the risk is low or when the cost of mitigation exceeds the potential impact, which is not the case here. 'Transfer' is wrong because cyber risk transfer (e.g., insurance) does not reduce the likelihood of an exploit, and it is not the first step when controls are missing. 'Avoid' is wrong because avoiding the risk would mean eliminating the application entirely, which is impossible given its criticality to business operations.
Community Comment Notes
Commenters consistently selected 'Mitigate' with a common rationale: the critical nature of the application demands risk reduction. One commenter said, 'Mitigate 1st since it is a legacy application and is critical,' while another highlighted that mitigation includes 'patching vulnerabilities, applying compensating controls.' None of the comments support other options, indicating strong consensus that mitigation is the textbook answer for this scenario.
Official Reference
Exam Strategy
Remember the four risk response strategies: mitigate, accept, transfer, avoid. When a business-critical asset has missing controls, mitigation is the automatic first choice because it actively reduces risk. Watch for keywords like 'critical' and 'not yet implemented'—they signal that the risk must be reduced, not accepted, transferred, or avoided.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →