Strategies of IT risk tolerance do NOT include which of the following?

A. Mitigation
B. Transference
C. Eradication
D. Elimination
E. Avoidance

Answer: C. Eradication

Explanation: “Eradication” is not a recognized strategy in IT risk tolerance. Common strategies include mitigation (reducing risk), transference (shifting risk to another party), elimination (completely removing risk), and avoidance (choosing not to engage in activities that create risk). Eradication is not typically used in this context, as it implies complete removal, which is often unrealistic in risk management.