A legacy web application cannot be patched without breaking a revenue system. After compensating controls are in place, an executive signs a memo stating the remaining exposure is acceptable for 18 months. Which vulnerability response best matches this decision?
Select an answer to reveal the explanation.
Short Explanation
Think of it like this: the business already weighed the cost of fixing the legacy app against the harm of leaving it exposed, then signed the paperwork. When leadership knowingly keeps residual risk, you call that formal risk acceptance. Don’t confuse it with adding controls or buying insurance—those are different responses.
Full Explanation
Formal risk acceptance is the vulnerability response used when a business owner knowingly retains residual risk after assessment and, often, after compensating controls have reduced the exposure to an agreed level. The decision is not a technical shortcut; it is an approved exception that documents the accepted exposure, the owner, the rationale, and a review period. It is appropriate when remediation is impractical or disproportionate, but the risk is understood and bounded. A mitigation response would be wrong because it seeks to lower likelihood or impact through controls, patching, configuration changes, or compensating measures rather than retaining the remaining exposure. A transfer response would be wrong because it shifts financial consequences to a third party, such as insurance or contractual indemnification, without eliminating the technical exposure. An avoidance response would be wrong because it removes the asset, service, or activity that creates the risk, such as decommissioning the application or blocking the business function. Exam caveat: risk acceptance must come from the accountable business owner, not the analyst, and it should include time-bound review conditions. Operational check: confirm the exception ticket contains the signed approval, affected asset, vulnerability identifiers, compensating controls, expiration date, and next review date.