A managed service provider assumes contractual responsibility for patching and remediation SLAs for externally exposed web servers, including penalties for missed deadlines. Which risk response best describes this arrangement?
Select an answer to reveal the explanation.
Short Explanation
Think of it like insurance: you still have a risk, but someone else is on the hook if it happens. Here, the MSP contract moves remediation responsibility and penalties, so you’re transferring risk, not avoiding it. Watch for the trap—patching still happens, so it isn’t pure avoidance.
Full Explanation
Contractual arrangements that assign remediation responsibility, service levels, and penalties to a third party are treated as risk transfer because the organization retains the underlying exposure but shifts accountability and often financial consequence to the provider. In vulnerability management, this commonly appears in managed patching, managed detection, or hosting agreements where the vendor agrees to meet SLAs for known flaws. The arrangement is not risk avoidance because the vulnerable system remains in use and the risk still exists; avoidance would require eliminating the exposure, such as decommissioning the service. It is not simple risk mitigation because mitigation describes direct controls that reduce likelihood or impact, such as applying patches, virtual patching, or segmentation; here the key concept is that responsibility is moved by contract. It is not risk acceptance because acceptance means knowingly retaining the risk without shifting responsibility or purchasing insurance. Exam caveat: Do not confuse the operational task of patching with the risk-response category; the question is asking who owns the risk, not which technical control is used. Operational check: Review the vendor agreement to confirm SLAs, breach penalties, reporting duties, and residual internal monitoring obligations.