A SOC analyst learns that a legacy internal service has an unpatchable vulnerability and no business owner needs it anymore. The team decommissions the service and removes it from the network. Which risk response does this represent?
Select an answer to reveal the explanation.
Short Explanation
Think of it like turning off a leaky old faucet instead of putting a bucket under it—you’re avoiding the risk, not managing it. Once the vulnerable legacy service is decommissioned, there’s nothing left to exploit, so your risk response is avoidance.
Full Explanation
Risk avoidance occurs when an organization removes the source of exposure entirely rather than reducing, transferring, or tolerating it. Decommissioning an unneeded component eliminates the vulnerable attack surface; the service cannot be exploited because it no longer exists. This differs from risk mitigation, which lowers likelihood or impact through controls such as patching, segmentation, or compensating controls while the asset remains in use. It also differs from risk transfer, which shifts some financial or operational consequence to another party through contracts, insurance, or service-level agreements; decommissioning does not assign residual risk to a third party. It differs from risk acceptance, which means knowingly retaining the risk when remediation is impractical or disproportionate to business value, typically with documented approval and monitoring. Exam caveat: elimination of an asset is avoidance only when the business no longer requires the asset; if the service remains required and is shut down temporarily, the response may be avoidance of exposure but not a sustainable mitigation. Operational check: confirm the decommissioning ticket includes service owner approval, removal from monitoring and access lists, and validation that dependent workflows are unaffected.