CompTIA Security+ (SY0-701) — Question 539

A company is aware of a given security risk related to a specific market segment. The business chooses not to accept responsibility and target their services to a different market segment. Which of the following describes this risk management strategy?

Answer options

Correct answer: C

Explanation

The correct answer is 'C. Avoid' because the company is actively choosing to steer clear of the risk by not engaging with the segment associated with it. 'A. Exemption' and 'B. Exception' do not accurately reflect the action of shifting focus to reduce risk, while 'D. Transfer' implies passing the risk to another party, which is not what the company is doing in this scenario.