CompTIA Security+ SY0-701 Risk Management Practice Test 1

 

Topic 24 Practice Test 1 covers Risk Management for CompTIA Security+ SY0-701 and maps to objective 5.2: Explain elements of the risk management process. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

Two requirements remain open in a risk-management workshop: risk review performed on a defined schedule; individual or role accountable for monitoring and making decisions about a specific risk. Which TWO options close those specific gaps? Choose TWO.

  1. Exposure factor
  2. Quantitative risk analysis
  3. Risk owner
  4. Risk avoidance
  5. Recurring risk assessment

Correct Answers: C, E

Correct Answers

 

 

Answer C is correct because Risk owner means the individual or role accountable for monitoring and making decisions about a specific risk. This option satisfies a specific requirement in the stem; Risk avoidance serves a treatment strategy that eliminates the activity or condition creating the risk and therefore is not interchangeable with it.

Answer E is correct because Recurring risk assessment means a risk review performed on a defined schedule. It belongs in the fixed-count answer set because it covers one of the stated requirements. Exposure factor instead serves the estimated percentage of asset value lost in one event and cannot replace this function.

Incorrect Answers

 

Answer A is incorrect because Exposure factor means the estimated percentage of asset value lost in one event. The question requires exactly 2 selections: Recurring risk assessment, Risk owner. This option falls outside that required set. For example, Risk owner is required for the individual or role accountable for monitoring and making decisions about a specific risk.

Answer B is incorrect because Quantitative risk analysis means risk analysis using numerical probabilities and financial or measurable impact values. The question requires exactly 2 selections: Recurring risk assessment, Risk owner. This option falls outside that required set. For example, Recurring risk assessment is required for a risk review performed on a defined schedule.

Answer D is incorrect because Risk avoidance means a treatment strategy that eliminates the activity or condition creating the risk. Every answer slot must map to a stated requirement. The correct set is Recurring risk assessment, Risk owner, so this option cannot replace one of those selections.

 

Question 2

An architect working on a risk-management workshop needs one capability that provides individual or role accountable for monitoring and making decisions about a specific risk and another that provides treatment decision to knowingly retain a risk within approved tolerance. Which TWO selections are the best match? Choose TWO.

  1. Mean time to repair (MTTR)
  2. Risk acceptance
  3. Risk transfer
  4. Risk tolerance
  5. Risk owner

Correct Answers: B, E

Correct Answers

 

 

Answer B is correct because Risk acceptance means a treatment decision to knowingly retain a risk within approved tolerance. One required function is exactly what this option provides. Risk tolerance may be useful elsewhere, but it is used for the acceptable amount of variation or exposure around objectives.

Answer E is correct because Risk owner means the individual or role accountable for monitoring and making decisions about a specific risk. One required function is exactly what this option provides. Risk tolerance may be useful elsewhere, but it is used for the acceptable amount of variation or exposure around objectives.

Incorrect Answers

 

Answer A is incorrect because Mean time to repair (MTTR) means the average time needed to restore a failed component or service. The scenario calls for Risk acceptance, Risk owner. Selecting this option would leave one of those required functions uncovered.

Answer C is incorrect because Risk transfer means a treatment strategy that shifts some financial or operational consequence to another party. The scenario calls for Risk acceptance, Risk owner. Selecting this option would leave one of those required functions uncovered.

Answer D is incorrect because Risk tolerance means the acceptable amount of variation or exposure around objectives. Every answer slot must map to a stated requirement. The correct set is Risk acceptance, Risk owner, so this option cannot replace one of those selections.

 

Question 3

To adapt risk understanding dynamically rather than only at periodic checkpoints, which security approach should be selected?

  1. Exposure factor
  2. Risk transfer
  3. Risk threshold
  4. Continuous risk assessment

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Continuous risk assessment means ongoing or frequently updated assessment using current data and events. The requirement maps directly to this function, whereas Exposure factor is aimed at the estimated percentage of asset value lost in one event.

Incorrect Answers

 

Answer A is incorrect because Exposure factor refers to the estimated percentage of asset value lost in one event. The key mismatch is functional: Continuous risk assessment addresses ongoing or frequently updated assessment using current data and events, the need stated by the question.

Answer B is incorrect because Risk transfer refers to a treatment strategy that shifts some financial or operational consequence to another party. That concept can be valid in another scenario, but this question is testing ongoing or frequently updated assessment using current data and events; Continuous risk assessment therefore fits the requirement more directly.

Answer C is incorrect because Risk threshold refers to a defined level at which a risk or indicator requires escalation or action. The concept is valid, but it does not match this stem. The required function is ongoing or frequently updated assessment using current data and events, which maps to Continuous risk assessment.

 

Question 4

The control set for a risk-management workshop must address both risk analysis using numerical probabilities and financial or measurable impact values and acceptable amount of variation or exposure around objectives. Which TWO choices map directly to those needs? Choose TWO.

  1. Risk register
  2. Risk tolerance
  3. Single loss expectancy (SLE)
  4. Risk transfer
  5. Quantitative risk analysis

Correct Answers: B, E

Correct Answers

 

 

Answer B is correct because Risk tolerance means the acceptable amount of variation or exposure around objectives. The fixed-count item needs this function in the answer set. Risk transfer covers a treatment strategy that shifts some financial or operational consequence to another party, a different requirement.

Answer E is correct because Quantitative risk analysis means risk analysis using numerical probabilities and financial or measurable impact values. It belongs in the fixed-count answer set because it covers one of the stated requirements. Risk transfer instead serves a treatment strategy that shifts some financial or operational consequence to another party and cannot replace this function.

Incorrect Answers

 

Answer A is incorrect because Risk register means a maintained record of identified risks, ratings, owners, responses, and status. The fixed-count answer set is Risk tolerance, Quantitative risk analysis; this option does not fill one of those named functions.

Answer C is incorrect because Single loss expectancy (SLE) means the expected financial loss from one occurrence of a risk event. Every answer slot must map to a stated requirement. The correct set is Risk tolerance, Quantitative risk analysis, so this option cannot replace one of those selections.

Answer D is incorrect because Risk transfer means a treatment strategy that shifts some financial or operational consequence to another party. The fixed-count answer set is Risk tolerance, Quantitative risk analysis; this option does not fill one of those named functions.

 

Question 5

To track risk decisions and accountability over time, which security approach should be selected?

  1. Risk register
  2. Qualitative risk analysis
  3. Single loss expectancy (SLE)
  4. Recurring risk assessment

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Risk register means a maintained record of identified risks, ratings, owners, responses, and status. The requirement maps directly to this function, whereas Single loss expectancy (SLE) is aimed at the expected financial loss from one occurrence of a risk event.

Incorrect Answers

 

Answer B is incorrect because Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high. The question is not asking for this function. It is testing a maintained record of identified risks, ratings, owners, responses, and status, so Risk register is the stronger fit.

Answer C is incorrect because Single loss expectancy (SLE) refers to the expected financial loss from one occurrence of a risk event. The scenario instead requires a maintained record of identified risks, ratings, owners, responses, and status, which is why Risk register is the better answer; this option serves the different function defined above.

Answer D is incorrect because Recurring risk assessment refers to a risk review performed on a defined schedule. This could be appropriate elsewhere, but the required function is a maintained record of identified risks, ratings, owners, responses, and status; that makes Risk register the precise choice.

 

Question 6

To set recovery priorities and objectives based on business impact, which security approach should be selected?

  1. Annualized loss expectancy (ALE)
  2. Business impact analysis (BIA)
  3. Recurring risk assessment
  4. Risk register

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Business impact analysis (BIA) means analysis of critical processes, dependencies, and consequences of disruption. This matches the requirement as written. Recurring risk assessment can be valid in another context, but it is used for a risk review performed on a defined schedule.

Incorrect Answers

 

Answer A is incorrect because Annualized loss expectancy (ALE) refers to the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO. This could be appropriate elsewhere, but the required function is analysis of critical processes, dependencies, and consequences of disruption; that makes Business impact analysis (BIA) the precise choice.

Answer C is incorrect because Recurring risk assessment refers to a risk review performed on a defined schedule. The scenario instead requires analysis of critical processes, dependencies, and consequences of disruption, which is why Business impact analysis (BIA) is the better answer; this option serves the different function defined above.

Answer D is incorrect because Risk register refers to a maintained record of identified risks, ratings, owners, responses, and status. The key mismatch is functional: Business impact analysis (BIA) addresses analysis of critical processes, dependencies, and consequences of disruption, the need stated by the question.

 

Question 7

The control set for a risk-management workshop must address both ongoing or frequently updated assessment using current data and events and acceptable amount of variation or exposure around objectives. Which TWO choices map directly to those needs? Choose TWO.

  1. Continuous risk assessment
  2. Risk threshold
  3. Risk tolerance
  4. Risk register
  5. Risk identification

Correct Answers: A, C

Correct Answers

 

 

Answer A is correct because Continuous risk assessment means ongoing or frequently updated assessment using current data and events. This selection maps directly to one of the named needs. Risk threshold addresses a defined level at which a risk or indicator requires escalation or action, so it does not satisfy the same slot.

Answer C is correct because Risk tolerance means the acceptable amount of variation or exposure around objectives. It belongs in the fixed-count answer set because it covers one of the stated requirements. Risk threshold instead serves a defined level at which a risk or indicator requires escalation or action and cannot replace this function.

Incorrect Answers

 

Answer B is incorrect because Risk threshold means a defined level at which a risk or indicator requires escalation or action. Every answer slot must map to a stated requirement. The correct set is Risk tolerance, Continuous risk assessment, so this option cannot replace one of those selections.

Answer D is incorrect because Risk register means a maintained record of identified risks, ratings, owners, responses, and status. The fixed-count answer set is Risk tolerance, Continuous risk assessment; this option does not fill one of those named functions.

Answer E is incorrect because Risk identification means the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives. The scenario calls for Risk tolerance, Continuous risk assessment. Selecting this option would leave one of those required functions uncovered.

 

Question 8

What is the overall amount and type of risk an organization is willing to pursue or retain?

  1. Mean time to repair (MTTR)
  2. Exposure factor
  3. Risk appetite
  4. Business impact analysis (BIA)

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Risk appetite means the overall amount and type of risk an organization is willing to pursue or retain. This is the precise fit for the scenario. Mean time to repair (MTTR) serves the different purpose of the average time needed to restore a failed component or service.

Incorrect Answers

 

Answer A is incorrect because Mean time to repair (MTTR) refers to the average time needed to restore a failed component or service. That concept can be valid in another scenario, but this question is testing the overall amount and type of risk an organization is willing to pursue or retain; Risk appetite therefore fits the requirement more directly.

Answer B is incorrect because Exposure factor refers to the estimated percentage of asset value lost in one event. The question is not asking for this function. It is testing the overall amount and type of risk an organization is willing to pursue or retain, so Risk appetite is the stronger fit.

Answer D is incorrect because Business impact analysis (BIA) refers to analysis of critical processes, dependencies, and consequences of disruption. The scenario instead requires the overall amount and type of risk an organization is willing to pursue or retain, which is why Risk appetite is the better answer; this option serves the different function defined above.

 

Question 9

To estimate expected losses and support cost-benefit decisions, which security approach should be selected?

  1. Recurring risk assessment
  2. Risk owner
  3. Single loss expectancy (SLE)
  4. Quantitative risk analysis

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Quantitative risk analysis means risk analysis using numerical probabilities and financial or measurable impact values. The requirement maps directly to this function, whereas Single loss expectancy (SLE) is aimed at the expected financial loss from one occurrence of a risk event.

Incorrect Answers

 

Answer A is incorrect because Recurring risk assessment refers to a risk review performed on a defined schedule. That concept can be valid in another scenario, but this question is testing risk analysis using numerical probabilities and financial or measurable impact values; Quantitative risk analysis therefore fits the requirement more directly.

Answer B is incorrect because Risk owner refers to the individual or role accountable for monitoring and making decisions about a specific risk. The concept is valid, but it does not match this stem. The required function is risk analysis using numerical probabilities and financial or measurable impact values, which maps to Quantitative risk analysis.

Answer C is incorrect because Single loss expectancy (SLE) refers to the expected financial loss from one occurrence of a risk event. This could be appropriate elsewhere, but the required function is risk analysis using numerical probabilities and financial or measurable impact values; that makes Quantitative risk analysis the precise choice.

 

Question 10

To provide early warning that risk may be increasing or controls may be weakening, which security approach should be selected?

  1. Risk appetite
  2. Risk acceptance
  3. Key risk indicator (KRI)
  4. Mean time to repair (MTTR)

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Key risk indicator (KRI) means a metric used to signal changes in risk exposure or conditions. That is the function the question is testing. Mean time to repair (MTTR) would instead be used for the average time needed to restore a failed component or service.

Incorrect Answers

 

Answer A is incorrect because Risk appetite refers to the overall amount and type of risk an organization is willing to pursue or retain. That concept can be valid in another scenario, but this question is testing a metric used to signal changes in risk exposure or conditions; Key risk indicator (KRI) therefore fits the requirement more directly.

Answer B is incorrect because Risk acceptance refers to a treatment decision to knowingly retain a risk within approved tolerance. The scenario instead requires a metric used to signal changes in risk exposure or conditions, which is why Key risk indicator (KRI) is the better answer; this option serves the different function defined above.

Answer D is incorrect because Mean time to repair (MTTR) refers to the average time needed to restore a failed component or service. The scenario instead requires a metric used to signal changes in risk exposure or conditions, which is why Key risk indicator (KRI) is the better answer; this option serves the different function defined above.

 

Question 11

What is the estimated percentage of asset value lost in one event?

  1. Exposure factor
  2. Risk mitigation
  3. Recovery time objective (RTO)
  4. Mean time between failures (MTBF)

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Exposure factor means the estimated percentage of asset value lost in one event. That is the function the question is testing. Mean time between failures (MTBF) would instead be used for the average operating time between failures for a repairable component or system.

Incorrect Answers

 

Answer B is incorrect because Risk mitigation refers to a treatment strategy that reduces likelihood or impact through controls. That concept can be valid in another scenario, but this question is testing the estimated percentage of asset value lost in one event; Exposure factor therefore fits the requirement more directly.

Answer C is incorrect because Recovery time objective (RTO) refers to the target maximum time a service or process should remain unavailable after disruption. That concept can be valid in another scenario, but this question is testing the estimated percentage of asset value lost in one event; Exposure factor therefore fits the requirement more directly.

Answer D is incorrect because Mean time between failures (MTBF) refers to the average operating time between failures for a repairable component or system. This could be appropriate elsewhere, but the required function is the estimated percentage of asset value lost in one event; that makes Exposure factor the precise choice.

 

Question 12

To estimate reliability and expected failure frequency, which security approach should be selected?

  1. Business impact analysis (BIA)
  2. Mean time between failures (MTBF)
  3. Risk tolerance
  4. Annualized rate of occurrence (ARO)

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Mean time between failures (MTBF) means the average operating time between failures for a repairable component or system. That is the function the question is testing. Annualized rate of occurrence (ARO) would instead be used for the expected frequency of a risk event within one year.

Incorrect Answers

 

Answer A is incorrect because Business impact analysis (BIA) refers to analysis of critical processes, dependencies, and consequences of disruption. The question is not asking for this function. It is testing the average operating time between failures for a repairable component or system, so Mean time between failures (MTBF) is the stronger fit.

Answer C is incorrect because Risk tolerance refers to the acceptable amount of variation or exposure around objectives. This could be appropriate elsewhere, but the required function is the average operating time between failures for a repairable component or system; that makes Mean time between failures (MTBF) the precise choice.

Answer D is incorrect because Annualized rate of occurrence (ARO) refers to the expected frequency of a risk event within one year. The question is not asking for this function. It is testing the average operating time between failures for a repairable component or system, so Mean time between failures (MTBF) is the stronger fit.

 

Question 13

Which risk review is performed on a defined schedule?

  1. Business impact analysis (BIA)
  2. Recurring risk assessment
  3. Risk owner
  4. Risk register

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Recurring risk assessment means a risk review performed on a defined schedule. The requirement maps directly to this function, whereas Risk register is aimed at a maintained record of identified risks, ratings, owners, responses, and status.

Incorrect Answers

 

Answer A is incorrect because Business impact analysis (BIA) refers to analysis of critical processes, dependencies, and consequences of disruption. This could be appropriate elsewhere, but the required function is a risk review performed on a defined schedule; that makes Recurring risk assessment the precise choice.

Answer C is incorrect because Risk owner refers to the individual or role accountable for monitoring and making decisions about a specific risk. The concept is valid, but it does not match this stem. The required function is a risk review performed on a defined schedule, which maps to Recurring risk assessment.

Answer D is incorrect because Risk register refers to a maintained record of identified risks, ratings, owners, responses, and status. The scenario instead requires a risk review performed on a defined schedule, which is why Recurring risk assessment is the better answer; this option serves the different function defined above.

 

Question 14

What is a maintained record of identified risks, ratings, owners, responses, and status?

  1. Risk register
  2. Risk identification
  3. Continuous risk assessment
  4. Key risk indicator (KRI)

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Risk register means a maintained record of identified risks, ratings, owners, responses, and status. That makes it the best answer here; Key risk indicator (KRI) addresses a metric used to signal changes in risk exposure or conditions, not the function requested in the stem.

Incorrect Answers

 

Answer B is incorrect because Risk identification refers to the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives. The scenario instead requires a maintained record of identified risks, ratings, owners, responses, and status, which is why Risk register is the better answer; this option serves the different function defined above.

Answer C is incorrect because Continuous risk assessment refers to ongoing or frequently updated assessment using current data and events. The key mismatch is functional: Risk register addresses a maintained record of identified risks, ratings, owners, responses, and status, the need stated by the question.

Answer D is incorrect because Key risk indicator (KRI) refers to a metric used to signal changes in risk exposure or conditions. The concept is valid, but it does not match this stem. The required function is a maintained record of identified risks, ratings, owners, responses, and status, which maps to Risk register.

 

Question 15

To define how much risk the organization is prepared to bear in a specific context, which security approach should be selected?

  1. Risk register
  2. Annualized loss expectancy (ALE)
  3. Risk tolerance
  4. Qualitative risk analysis

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Risk tolerance means the acceptable amount of variation or exposure around objectives. This matches the requirement as written. Annualized loss expectancy (ALE) can be valid in another context, but it is used for the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.

Incorrect Answers

 

Answer A is incorrect because Risk register refers to a maintained record of identified risks, ratings, owners, responses, and status. This could be appropriate elsewhere, but the required function is the acceptable amount of variation or exposure around objectives; that makes Risk tolerance the precise choice.

Answer B is incorrect because Annualized loss expectancy (ALE) refers to the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO. The key mismatch is functional: Risk tolerance addresses the acceptable amount of variation or exposure around objectives, the need stated by the question.

Answer D is incorrect because Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high. The concept is valid, but it does not match this stem. The required function is the acceptable amount of variation or exposure around objectives, which maps to Risk tolerance.

 

Question 16

A review during a risk-management workshop identifies two gaps. One requires individual or role accountable for monitoring and making decisions about a specific risk. The other requires treatment strategy that reduces likelihood or impact through controls. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Risk avoidance
  2. Risk owner
  3. Recurring risk assessment
  4. Risk mitigation
  5. Annualized loss expectancy (ALE)

Correct Answers: B, D

Correct Answers

 

 

Answer B is correct because Risk owner means the individual or role accountable for monitoring and making decisions about a specific risk. The fixed-count item needs this function in the answer set. Annualized loss expectancy (ALE) covers the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO, a different requirement.

Answer D is correct because Risk mitigation means a treatment strategy that reduces likelihood or impact through controls. The fixed-count item needs this function in the answer set. Annualized loss expectancy (ALE) covers the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO, a different requirement.

Incorrect Answers

 

Answer A is incorrect because Risk avoidance means a treatment strategy that eliminates the activity or condition creating the risk. The fixed-count answer set is Risk owner, Risk mitigation; this option does not fill one of those named functions.

Answer C is incorrect because Recurring risk assessment means a risk review performed on a defined schedule. The scenario calls for Risk owner, Risk mitigation. Selecting this option would leave one of those required functions uncovered. For example, Risk mitigation is required for a treatment strategy that reduces likelihood or impact through controls.

Answer E is incorrect because Annualized loss expectancy (ALE) means the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO. The fixed-count answer set is Risk owner, Risk mitigation; this option does not fill one of those named functions.

 

Question 17

During a risk-management workshop, three requirements must be addressed: (1) expected frequency of a risk event within one year; (2) maintained record of identified risks, ratings, owners, responses, and status; and (3) average operating time between failures for a repairable component or system. Which THREE choices best satisfy them? Choose THREE.

  1. Risk register
  2. Mean time between failures (MTBF)
  3. Annualized loss expectancy (ALE)
  4. Risk mitigation
  5. Annualized rate of occurrence (ARO)
  6. Exposure factor

Correct Answers: A, B, E

Correct Answers

 

 

Answer A is correct because Risk register means a maintained record of identified risks, ratings, owners, responses, and status. One required function is exactly what this option provides. Risk mitigation may be useful elsewhere, but it is used for a treatment strategy that reduces likelihood or impact through controls.

Answer B is correct because Mean time between failures (MTBF) means the average operating time between failures for a repairable component or system. This option satisfies a specific requirement in the stem; Exposure factor serves the estimated percentage of asset value lost in one event and therefore is not interchangeable with it.

Answer E is correct because Annualized rate of occurrence (ARO) means the expected frequency of a risk event within one year. The fixed-count item needs this function in the answer set. Annualized loss expectancy (ALE) covers the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO, a different requirement.

Incorrect Answers

 

Answer C is incorrect because Annualized loss expectancy (ALE) means the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO. Every answer slot must map to a stated requirement. The correct set is Risk register, Mean time between failures (MTBF), Annualized rate of occurrence (ARO), so this option cannot replace one of those selections.

Answer D is incorrect because Risk mitigation means a treatment strategy that reduces likelihood or impact through controls. The fixed-count answer set is Risk register, Mean time between failures (MTBF), Annualized rate of occurrence (ARO); this option does not fill one of those named functions.

Answer F is incorrect because Exposure factor means the estimated percentage of asset value lost in one event. The scenario calls for Risk register, Mean time between failures (MTBF), Annualized rate of occurrence (ARO). Selecting this option would leave one of those required functions uncovered.

 

Question 18

Which term describes risk analysis using numerical probabilities and financial or measurable impact values?

  1. Risk owner
  2. Risk threshold
  3. Recovery point objective (RPO)
  4. Quantitative risk analysis

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Quantitative risk analysis means risk analysis using numerical probabilities and financial or measurable impact values. That is the function the question is testing. Recovery point objective (RPO) would instead be used for the target maximum acceptable amount of data loss measured backward in time.

Incorrect Answers

 

Answer A is incorrect because Risk owner refers to the individual or role accountable for monitoring and making decisions about a specific risk. The concept is valid, but it does not match this stem. The required function is risk analysis using numerical probabilities and financial or measurable impact values, which maps to Quantitative risk analysis. This question specifically tests the requirement represented by Quantitative risk analysis.

Answer B is incorrect because Risk threshold refers to a defined level at which a risk or indicator requires escalation or action. That concept can be valid in another scenario, but this question is testing risk analysis using numerical probabilities and financial or measurable impact values; Quantitative risk analysis therefore fits the requirement more directly.

Answer C is incorrect because Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time. That concept can be valid in another scenario, but this question is testing risk analysis using numerical probabilities and financial or measurable impact values; Quantitative risk analysis therefore fits the requirement more directly.

 

Question 19

To determine how current recovered data must be, which security approach should be selected?

  1. Risk mitigation
  2. Risk appetite
  3. Recovery point objective (RPO)
  4. Quantitative risk analysis

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Recovery point objective (RPO) means the target maximum acceptable amount of data loss measured backward in time. That makes it the best answer here; Risk mitigation addresses a treatment strategy that reduces likelihood or impact through controls, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Risk mitigation refers to a treatment strategy that reduces likelihood or impact through controls. That concept can be valid in another scenario, but this question is testing the target maximum acceptable amount of data loss measured backward in time; Recovery point objective (RPO) therefore fits the requirement more directly.

Answer B is incorrect because Risk appetite refers to the overall amount and type of risk an organization is willing to pursue or retain. This could be appropriate elsewhere, but the required function is the target maximum acceptable amount of data loss measured backward in time; that makes Recovery point objective (RPO) the precise choice.

Answer D is incorrect because Quantitative risk analysis refers to risk analysis using numerical probabilities and financial or measurable impact values. The concept is valid, but it does not match this stem. The required function is the target maximum acceptable amount of data loss measured backward in time, which maps to Recovery point objective (RPO).

 

Question 20

To ensure someone has responsibility for treatment and acceptance decisions, which security approach should be selected?

  1. Risk transfer
  2. Risk owner
  3. Mean time to repair (MTTR)
  4. Annualized rate of occurrence (ARO)

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Risk owner means the individual or role accountable for monitoring and making decisions about a specific risk. That is the function the question is testing. Annualized rate of occurrence (ARO) would instead be used for the expected frequency of a risk event within one year.

Incorrect Answers

 

Answer A is incorrect because Risk transfer refers to a treatment strategy that shifts some financial or operational consequence to another party. The question is not asking for this function. It is testing the individual or role accountable for monitoring and making decisions about a specific risk, so Risk owner is the stronger fit.

Answer C is incorrect because Mean time to repair (MTTR) refers to the average time needed to restore a failed component or service. The question is not asking for this function. It is testing the individual or role accountable for monitoring and making decisions about a specific risk, so Risk owner is the stronger fit.

Answer D is incorrect because Annualized rate of occurrence (ARO) refers to the expected frequency of a risk event within one year. The concept is valid, but it does not match this stem. The required function is the individual or role accountable for monitoring and making decisions about a specific risk, which maps to Risk owner.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!