Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.
This chapter covers the following official CompTIA Security+ Certification exam objectives:
• Analyze and differentiate among types of mitigation and deterrent techniques
• Implement assessment tools and techniques to discover security threats and vulnerabilities
(For more information on the official CompTIA Security+ Certification exam topics, see the “About the CompTIA Security+ Certification Exam” section in the Introduction.)
In most situations it is not possible nor even prudent to try to completely eliminate risks. Remember that risk is typically a result of some type of benefit gained. One might be able to eliminate the risk of being involved in a vehicle accident, but this would mean that they never get inside of a vehicle. Of course, however, there is an important benefit derived as a result and thus a tradeoff. Of course, even deciding to walk everywhere instead brings its own risks. Just as one who drives a vehicle buys insurance and wears a seatbelt, for example, organizations look to reduce or mitigate risks when it comes to information security.