CompTIA CySA+CS0-002 – Question116

An organization has the following risk mitigation policies:
– Risks without compensating controls will be mitigated first if the risk value is greater than $50,000.
– Other risk mitigation will be prioritized based on risk value.
The following risks have been identified:

Which of the following is the order of priority for risk mitigation from highest to lowest?

A.
A, C, D, B
B. B, C, D, A
C. C, B, A, D
D. C, D, A, B
E. D, C, B, A

Correct Answer: C