CompTIA Security+ SY0-701 Risk Management Practice Test 2

 

Topic 24 Practice Test 2 covers Risk Management for CompTIA Security+ SY0-701 and maps to objective 5.2: Explain elements of the risk management process. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

To re-evaluate risk as systems, threats, and business conditions change, which security approach should be selected?

  1. Mean time to repair (MTTR)
  2. Risk avoidance
  3. Recurring risk assessment
  4. Recovery time objective (RTO)

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Recurring risk assessment means a risk review performed on a defined schedule. This matches the requirement as written. Mean time to repair (MTTR) can be valid in another context, but it is used for the average time needed to restore a failed component or service.

Incorrect Answers

 

Answer A is incorrect because Mean time to repair (MTTR) refers to the average time needed to restore a failed component or service. That concept can be valid in another scenario, but this question is testing a risk review performed on a defined schedule; Recurring risk assessment therefore fits the requirement more directly.

Answer B is incorrect because Risk avoidance refers to a treatment strategy that eliminates the activity or condition creating the risk. The concept is valid, but it does not match this stem. The required function is a risk review performed on a defined schedule, which maps to Recurring risk assessment.

Answer D is incorrect because Recovery time objective (RTO) refers to the target maximum time a service or process should remain unavailable after disruption. The scenario instead requires a risk review performed on a defined schedule, which is why Recurring risk assessment is the better answer; this option serves the different function defined above.

 

Question 2

To calculate the loss portion used in quantitative risk analysis, which security approach should be selected?

  1. Annualized loss expectancy (ALE)
  2. Business impact analysis (BIA)
  3. Risk threshold
  4. Exposure factor

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Exposure factor means the estimated percentage of asset value lost in one event. The deciding point is functional fit: this option covers the stated need, while Business impact analysis (BIA) addresses analysis of critical processes, dependencies, and consequences of disruption.

Incorrect Answers

 

Answer A is incorrect because Annualized loss expectancy (ALE) refers to the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO. The question is not asking for this function. It is testing the estimated percentage of asset value lost in one event, so Exposure factor is the stronger fit.

Answer B is incorrect because Business impact analysis (BIA) refers to analysis of critical processes, dependencies, and consequences of disruption. This could be appropriate elsewhere, but the required function is the estimated percentage of asset value lost in one event; that makes Exposure factor the precise choice.

Answer C is incorrect because Risk threshold refers to a defined level at which a risk or indicator requires escalation or action. That concept can be valid in another scenario, but this question is testing the estimated percentage of asset value lost in one event; Exposure factor therefore fits the requirement more directly.

 

Question 3

To compare annualized financial exposure across risks, which security approach should be selected?

  1. Continuous risk assessment
  2. Risk appetite
  3. Risk acceptance
  4. Annualized loss expectancy (ALE)

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Annualized loss expectancy (ALE) means the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO. That is the function the question is testing. Risk acceptance would instead be used for a treatment decision to knowingly retain a risk within approved tolerance.

Incorrect Answers

 

Answer A is incorrect because Continuous risk assessment refers to ongoing or frequently updated assessment using current data and events. The scenario instead requires the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO, which is why Annualized loss expectancy (ALE) is the better answer; this option serves the different function defined above.

Answer B is incorrect because Risk appetite refers to the overall amount and type of risk an organization is willing to pursue or retain. That concept can be valid in another scenario, but this question is testing the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO; Annualized loss expectancy (ALE) therefore fits the requirement more directly.

Answer C is incorrect because Risk acceptance refers to a treatment decision to knowingly retain a risk within approved tolerance. That concept can be valid in another scenario, but this question is testing the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO; Annualized loss expectancy (ALE) therefore fits the requirement more directly.

 

Question 4

What is the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO?

  1. Qualitative risk analysis
  2. Annualized loss expectancy (ALE)
  3. Risk identification
  4. Key risk indicator (KRI)

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Annualized loss expectancy (ALE) means the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO. This is the precise fit for the scenario. Qualitative risk analysis serves the different purpose of risk analysis using descriptive or ordinal ratings such as low, medium, and high.

Incorrect Answers

 

Answer A is incorrect because Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high. The question is not asking for this function. It is testing the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO, so Annualized loss expectancy (ALE) is the stronger fit.

Answer C is incorrect because Risk identification refers to the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives. This could be appropriate elsewhere, but the required function is the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO; that makes Annualized loss expectancy (ALE) the precise choice.

Answer D is incorrect because Key risk indicator (KRI) refers to a metric used to signal changes in risk exposure or conditions. That concept can be valid in another scenario, but this question is testing the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO; Annualized loss expectancy (ALE) therefore fits the requirement more directly.

 

Question 5

What is the expected frequency of a risk event within one year?

  1. Recurring risk assessment
  2. Risk owner
  3. Key risk indicator (KRI)
  4. Annualized rate of occurrence (ARO)

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Annualized rate of occurrence (ARO) means the expected frequency of a risk event within one year. That makes it the best answer here; Key risk indicator (KRI) addresses a metric used to signal changes in risk exposure or conditions, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Recurring risk assessment refers to a risk review performed on a defined schedule. The concept is valid, but it does not match this stem. The required function is the expected frequency of a risk event within one year, which maps to Annualized rate of occurrence (ARO).

Answer B is incorrect because Risk owner refers to the individual or role accountable for monitoring and making decisions about a specific risk. That concept can be valid in another scenario, but this question is testing the expected frequency of a risk event within one year; Annualized rate of occurrence (ARO) therefore fits the requirement more directly.

Answer C is incorrect because Key risk indicator (KRI) refers to a metric used to signal changes in risk exposure or conditions. The question is not asking for this function. It is testing the expected frequency of a risk event within one year, so Annualized rate of occurrence (ARO) is the stronger fit.

 

Question 6

The control set for a risk-management workshop must address both risk analysis using numerical probabilities and financial or measurable impact values and average time needed to restore a failed component or service. Which TWO choices map directly to those needs? Choose TWO.

  1. Quantitative risk analysis
  2. Risk mitigation
  3. Mean time to repair (MTTR)
  4. Business impact analysis (BIA)
  5. Mean time between failures (MTBF)

Correct Answers: A, C

Correct Answers

 

 

Answer A is correct because Quantitative risk analysis means risk analysis using numerical probabilities and financial or measurable impact values. This selection maps directly to one of the named needs. Mean time between failures (MTBF) addresses the average operating time between failures for a repairable component or system, so it does not satisfy the same slot.

Answer C is correct because Mean time to repair (MTTR) means the average time needed to restore a failed component or service. One required function is exactly what this option provides. Mean time between failures (MTBF) may be useful elsewhere, but it is used for the average operating time between failures for a repairable component or system.

Incorrect Answers

 

Answer B is incorrect because Risk mitigation means a treatment strategy that reduces likelihood or impact through controls. The fixed-count answer set is Mean time to repair (MTTR), Quantitative risk analysis; this option does not fill one of those named functions.

Answer D is incorrect because Business impact analysis (BIA) means analysis of critical processes, dependencies, and consequences of disruption. The scenario calls for Mean time to repair (MTTR), Quantitative risk analysis. Selecting this option would leave one of those required functions uncovered.

Answer E is incorrect because Mean time between failures (MTBF) means the average operating time between failures for a repairable component or system. The required choices are Mean time to repair (MTTR), Quantitative risk analysis. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 7

A security plan created during a risk-management workshop must provide treatment decision to knowingly retain a risk within approved tolerance, target maximum acceptable amount of data loss measured backward in time, and average time needed to restore a failed component or service. Which THREE options should be selected? Choose THREE.

  1. Risk acceptance
  2. Recovery point objective (RPO)
  3. Quantitative risk analysis
  4. Single loss expectancy (SLE)
  5. Mean time to repair (MTTR)
  6. Risk identification

Correct Answers: A, B, E

Correct Answers

 

 

Answer A is correct because Risk acceptance means a treatment decision to knowingly retain a risk within approved tolerance. This option satisfies a specific requirement in the stem; Risk identification serves the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives and therefore is not interchangeable with it.

Answer B is correct because Recovery point objective (RPO) means the target maximum acceptable amount of data loss measured backward in time. This selection maps directly to one of the named needs. Single loss expectancy (SLE) addresses the expected financial loss from one occurrence of a risk event, so it does not satisfy the same slot.

Answer E is correct because Mean time to repair (MTTR) means the average time needed to restore a failed component or service. One required function is exactly what this option provides. Risk identification may be useful elsewhere, but it is used for the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives.

Incorrect Answers

 

Answer C is incorrect because Quantitative risk analysis means risk analysis using numerical probabilities and financial or measurable impact values. The question requires exactly 3 selections: Mean time to repair (MTTR), Risk acceptance, Recovery point objective (RPO). This option falls outside that required set.

Answer D is incorrect because Single loss expectancy (SLE) means the expected financial loss from one occurrence of a risk event. The required choices are Mean time to repair (MTTR), Risk acceptance, Recovery point objective (RPO). Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer F is incorrect because Risk identification means the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives. Every answer slot must map to a stated requirement. The correct set is Mean time to repair (MTTR), Risk acceptance, Recovery point objective (RPO), so this option cannot replace one of those selections.

 

Question 8

To convert event likelihood into an annual frequency estimate, which security approach should be selected?

  1. Risk transfer
  2. Quantitative risk analysis
  3. Risk register
  4. Annualized rate of occurrence (ARO)

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Annualized rate of occurrence (ARO) means the expected frequency of a risk event within one year. The requirement maps directly to this function, whereas Risk transfer is aimed at a treatment strategy that shifts some financial or operational consequence to another party.

Incorrect Answers

 

Answer A is incorrect because Risk transfer refers to a treatment strategy that shifts some financial or operational consequence to another party. The key mismatch is functional: Annualized rate of occurrence (ARO) addresses the expected frequency of a risk event within one year, the need stated by the question.

Answer B is incorrect because Quantitative risk analysis refers to risk analysis using numerical probabilities and financial or measurable impact values. The scenario instead requires the expected frequency of a risk event within one year, which is why Annualized rate of occurrence (ARO) is the better answer; this option serves the different function defined above.

Answer C is incorrect because Risk register refers to a maintained record of identified risks, ratings, owners, responses, and status. This could be appropriate elsewhere, but the required function is the expected frequency of a risk event within one year; that makes Annualized rate of occurrence (ARO) the precise choice.

 

Question 9

The control set for a risk-management workshop must address both target maximum acceptable amount of data loss measured backward in time and average time needed to restore a failed component or service. Which TWO choices map directly to those needs? Choose TWO.

  1. Exposure factor
  2. Annualized rate of occurrence (ARO)
  3. Mean time to repair (MTTR)
  4. Recovery point objective (RPO)
  5. Mean time between failures (MTBF)

Correct Answers: C, D

Correct Answers

 

 

Answer C is correct because Mean time to repair (MTTR) means the average time needed to restore a failed component or service. This option satisfies a specific requirement in the stem; Annualized rate of occurrence (ARO) serves the expected frequency of a risk event within one year and therefore is not interchangeable with it.

Answer D is correct because Recovery point objective (RPO) means the target maximum acceptable amount of data loss measured backward in time. This option satisfies a specific requirement in the stem; Exposure factor serves the estimated percentage of asset value lost in one event and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because Exposure factor means the estimated percentage of asset value lost in one event. The question requires exactly 2 selections: Mean time to repair (MTTR), Recovery point objective (RPO). This option falls outside that required set.

Answer B is incorrect because Annualized rate of occurrence (ARO) means the expected frequency of a risk event within one year. Every answer slot must map to a stated requirement. The correct set is Mean time to repair (MTTR), Recovery point objective (RPO), so this option cannot replace one of those selections.

Answer E is incorrect because Mean time between failures (MTBF) means the average operating time between failures for a repairable component or system. Every answer slot must map to a stated requirement. The correct set is Mean time to repair (MTTR), Recovery point objective (RPO), so this option cannot replace one of those selections.

 

Question 10

During a risk-management workshop, the team has two independent requirements: (1) maintained record of identified risks, ratings, owners, responses, and status; and (2) overall amount and type of risk an organization is willing to pursue or retain. Which TWO choices best satisfy those requirements? Choose TWO.

  1. Quantitative risk analysis
  2. Risk register
  3. Recovery point objective (RPO)
  4. Annualized loss expectancy (ALE)
  5. Risk appetite

Correct Answers: B, E

Correct Answers

 

 

Answer B is correct because Risk register means a maintained record of identified risks, ratings, owners, responses, and status. It belongs in the fixed-count answer set because it covers one of the stated requirements. Annualized loss expectancy (ALE) instead serves the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO and cannot replace this function.

Answer E is correct because Risk appetite means the overall amount and type of risk an organization is willing to pursue or retain. One required function is exactly what this option provides. Annualized loss expectancy (ALE) may be useful elsewhere, but it is used for the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.

Incorrect Answers

 

Answer A is incorrect because Quantitative risk analysis means risk analysis using numerical probabilities and financial or measurable impact values. The scenario calls for Risk register, Risk appetite. Selecting this option would leave one of those required functions uncovered.

Answer C is incorrect because Recovery point objective (RPO) means the target maximum acceptable amount of data loss measured backward in time. The question requires exactly 2 selections: Risk register, Risk appetite. This option falls outside that required set.

Answer D is incorrect because Annualized loss expectancy (ALE) means the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO. The required choices are Risk register, Risk appetite. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 11

What is a treatment decision to knowingly retain a risk within approved tolerance?

  1. Risk acceptance
  2. Recovery point objective (RPO)
  3. Annualized rate of occurrence (ARO)
  4. Risk identification

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Risk acceptance means a treatment decision to knowingly retain a risk within approved tolerance. This matches the requirement as written. Annualized rate of occurrence (ARO) can be valid in another context, but it is used for the expected frequency of a risk event within one year.

Incorrect Answers

 

Answer B is incorrect because Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time. This could be appropriate elsewhere, but the required function is a treatment decision to knowingly retain a risk within approved tolerance; that makes Risk acceptance the precise choice.

Answer C is incorrect because Annualized rate of occurrence (ARO) refers to the expected frequency of a risk event within one year. The scenario instead requires a treatment decision to knowingly retain a risk within approved tolerance, which is why Risk acceptance is the better answer; this option serves the different function defined above.

Answer D is incorrect because Risk identification refers to the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives. This could be appropriate elsewhere, but the required function is a treatment decision to knowingly retain a risk within approved tolerance; that makes Risk acceptance the precise choice.

 

Question 12

To compare risks when precise monetary data is unavailable or unnecessary, which security approach should be selected?

  1. Qualitative risk analysis
  2. Risk threshold
  3. Recurring risk assessment
  4. Quantitative risk analysis

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Qualitative risk analysis means risk analysis using descriptive or ordinal ratings such as low, medium, and high. This matches the requirement as written. Quantitative risk analysis can be valid in another context, but it is used for risk analysis using numerical probabilities and financial or measurable impact values.

Incorrect Answers

 

Answer B is incorrect because Risk threshold refers to a defined level at which a risk or indicator requires escalation or action. The question is not asking for this function. It is testing risk analysis using descriptive or ordinal ratings such as low, medium, and high, so Qualitative risk analysis is the stronger fit.

Answer C is incorrect because Recurring risk assessment refers to a risk review performed on a defined schedule. This could be appropriate elsewhere, but the required function is risk analysis using descriptive or ordinal ratings such as low, medium, and high; that makes Qualitative risk analysis the precise choice.

Answer D is incorrect because Quantitative risk analysis refers to risk analysis using numerical probabilities and financial or measurable impact values. The scenario instead requires risk analysis using descriptive or ordinal ratings such as low, medium, and high, which is why Qualitative risk analysis is the better answer; this option serves the different function defined above.

 

Question 13

To use insurance or contracts to redistribute defined impacts, which security approach should be selected?

  1. Recovery time objective (RTO)
  2. Risk identification
  3. Risk transfer
  4. Recurring risk assessment

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Risk transfer means a treatment strategy that shifts some financial or operational consequence to another party. This is the precise fit for the scenario. Recovery time objective (RTO) serves the different purpose of the target maximum time a service or process should remain unavailable after disruption.

Incorrect Answers

 

Answer A is incorrect because Recovery time objective (RTO) refers to the target maximum time a service or process should remain unavailable after disruption. The concept is valid, but it does not match this stem. The required function is a treatment strategy that shifts some financial or operational consequence to another party, which maps to Risk transfer.

Answer B is incorrect because Risk identification refers to the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives. That concept can be valid in another scenario, but this question is testing a treatment strategy that shifts some financial or operational consequence to another party; Risk transfer therefore fits the requirement more directly.

Answer D is incorrect because Recurring risk assessment refers to a risk review performed on a defined schedule. The question is not asking for this function. It is testing a treatment strategy that shifts some financial or operational consequence to another party, so Risk transfer is the stronger fit.

 

Question 14

What is the target maximum time a service or process should remain unavailable after disruption?

  1. Annualized loss expectancy (ALE)
  2. Recovery time objective (RTO)
  3. Recovery point objective (RPO)
  4. Single loss expectancy (SLE)

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Recovery time objective (RTO) means the target maximum time a service or process should remain unavailable after disruption. That is the function the question is testing. Annualized loss expectancy (ALE) would instead be used for the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.

Incorrect Answers

 

Answer A is incorrect because Annualized loss expectancy (ALE) refers to the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO. The key mismatch is functional: Recovery time objective (RTO) addresses the target maximum time a service or process should remain unavailable after disruption, the need stated by the question.

Answer C is incorrect because Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time. This could be appropriate elsewhere, but the required function is the target maximum time a service or process should remain unavailable after disruption; that makes Recovery time objective (RTO) the precise choice.

Answer D is incorrect because Single loss expectancy (SLE) refers to the expected financial loss from one occurrence of a risk event. The concept is valid, but it does not match this stem. The required function is the target maximum time a service or process should remain unavailable after disruption, which maps to Recovery time objective (RTO).

 

Question 15

An architect working on a risk-management workshop needs one capability that provides process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives and another that provides treatment decision to knowingly retain a risk within approved tolerance. Which TWO selections are the best match? Choose TWO.

  1. Risk acceptance
  2. Key risk indicator (KRI)
  3. Single loss expectancy (SLE)
  4. Risk identification
  5. Qualitative risk analysis

Correct Answers: A, D

Correct Answers

 

 

Answer A is correct because Risk acceptance means a treatment decision to knowingly retain a risk within approved tolerance. One required function is exactly what this option provides. Key risk indicator (KRI) may be useful elsewhere, but it is used for a metric used to signal changes in risk exposure or conditions.

Answer D is correct because Risk identification means the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives. One required function is exactly what this option provides. Key risk indicator (KRI) may be useful elsewhere, but it is used for a metric used to signal changes in risk exposure or conditions.

Incorrect Answers

 

Answer B is incorrect because Key risk indicator (KRI) means a metric used to signal changes in risk exposure or conditions. The fixed-count answer set is Risk identification, Risk acceptance; this option does not fill one of those named functions.

Answer C is incorrect because Single loss expectancy (SLE) means the expected financial loss from one occurrence of a risk event. Every answer slot must map to a stated requirement. The correct set is Risk identification, Risk acceptance, so this option cannot replace one of those selections.

Answer E is incorrect because Qualitative risk analysis means risk analysis using descriptive or ordinal ratings such as low, medium, and high. The required choices are Risk identification, Risk acceptance. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 16

To create the set of risks that need analysis and treatment, which security approach should be selected?

  1. Risk appetite
  2. Risk identification
  3. Risk tolerance
  4. Qualitative risk analysis

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Risk identification means the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives. That is the function the question is testing. Risk tolerance would instead be used for the acceptable amount of variation or exposure around objectives.

Incorrect Answers

 

Answer A is incorrect because Risk appetite refers to the overall amount and type of risk an organization is willing to pursue or retain. The concept is valid, but it does not match this stem. The required function is the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives, which maps to Risk identification.

Answer C is incorrect because Risk tolerance refers to the acceptable amount of variation or exposure around objectives. The concept is valid, but it does not match this stem. The required function is the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives, which maps to Risk identification.

Answer D is incorrect because Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high. That concept can be valid in another scenario, but this question is testing the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives; Risk identification therefore fits the requirement more directly.

 

Question 17

Which metric is used to signal changes in risk exposure or conditions?

  1. Risk mitigation
  2. Business impact analysis (BIA)
  3. Key risk indicator (KRI)
  4. Recovery time objective (RTO)

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Key risk indicator (KRI) means a metric used to signal changes in risk exposure or conditions. This matches the requirement as written. Business impact analysis (BIA) can be valid in another context, but it is used for analysis of critical processes, dependencies, and consequences of disruption.

Incorrect Answers

 

Answer A is incorrect because Risk mitigation refers to a treatment strategy that reduces likelihood or impact through controls. The key mismatch is functional: Key risk indicator (KRI) addresses a metric used to signal changes in risk exposure or conditions, the need stated by the question.

Answer B is incorrect because Business impact analysis (BIA) refers to analysis of critical processes, dependencies, and consequences of disruption. That concept can be valid in another scenario, but this question is testing a metric used to signal changes in risk exposure or conditions; Key risk indicator (KRI) therefore fits the requirement more directly.

Answer D is incorrect because Recovery time objective (RTO) refers to the target maximum time a service or process should remain unavailable after disruption. The question is not asking for this function. It is testing a metric used to signal changes in risk exposure or conditions, so Key risk indicator (KRI) is the stronger fit.

 

Question 18

To estimate the monetary impact of a single incident, which security approach should be selected?

  1. Single loss expectancy (SLE)
  2. Risk appetite
  3. Qualitative risk analysis
  4. Recovery point objective (RPO)

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Single loss expectancy (SLE) means the expected financial loss from one occurrence of a risk event. The deciding point is functional fit: this option covers the stated need, while Recovery point objective (RPO) addresses the target maximum acceptable amount of data loss measured backward in time.

Incorrect Answers

 

Answer B is incorrect because Risk appetite refers to the overall amount and type of risk an organization is willing to pursue or retain. The question is not asking for this function. It is testing the expected financial loss from one occurrence of a risk event, so Single loss expectancy (SLE) is the stronger fit.

Answer C is incorrect because Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high. The question is not asking for this function. It is testing the expected financial loss from one occurrence of a risk event, so Single loss expectancy (SLE) is the stronger fit.

Answer D is incorrect because Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time. The question is not asking for this function. It is testing the expected financial loss from one occurrence of a risk event, so Single loss expectancy (SLE) is the stronger fit.

 

Question 19

During a risk-management workshop, the team has two independent requirements: (1) risk review performed on a defined schedule; and (2) target maximum time a service or process should remain unavailable after disruption. Which TWO choices best satisfy those requirements? Choose TWO.

  1. Single loss expectancy (SLE)
  2. Recurring risk assessment
  3. Recovery time objective (RTO)
  4. Mean time between failures (MTBF)
  5. Risk appetite

Correct Answers: B, C

Correct Answers

 

 

Answer B is correct because Recurring risk assessment means a risk review performed on a defined schedule. It belongs in the fixed-count answer set because it covers one of the stated requirements. Mean time between failures (MTBF) instead serves the average operating time between failures for a repairable component or system and cannot replace this function.

Answer C is correct because Recovery time objective (RTO) means the target maximum time a service or process should remain unavailable after disruption. One required function is exactly what this option provides. Risk appetite may be useful elsewhere, but it is used for the overall amount and type of risk an organization is willing to pursue or retain.

Incorrect Answers

 

Answer A is incorrect because Single loss expectancy (SLE) means the expected financial loss from one occurrence of a risk event. Every answer slot must map to a stated requirement. The correct set is Recovery time objective (RTO), Recurring risk assessment, so this option cannot replace one of those selections.

Answer D is incorrect because Mean time between failures (MTBF) means the average operating time between failures for a repairable component or system. The scenario calls for Recovery time objective (RTO), Recurring risk assessment. Selecting this option would leave one of those required functions uncovered.

Answer E is incorrect because Risk appetite means the overall amount and type of risk an organization is willing to pursue or retain. The required choices are Recovery time objective (RTO), Recurring risk assessment. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 20

What is the average time needed to restore a failed component or service?

  1. Risk avoidance
  2. Single loss expectancy (SLE)
  3. Mean time to repair (MTTR)
  4. Recovery point objective (RPO)

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Mean time to repair (MTTR) means the average time needed to restore a failed component or service. The requirement maps directly to this function, whereas Single loss expectancy (SLE) is aimed at the expected financial loss from one occurrence of a risk event.

Incorrect Answers

 

Answer A is incorrect because Risk avoidance refers to a treatment strategy that eliminates the activity or condition creating the risk. The question is not asking for this function. It is testing the average time needed to restore a failed component or service, so Mean time to repair (MTTR) is the stronger fit.

Answer B is incorrect because Single loss expectancy (SLE) refers to the expected financial loss from one occurrence of a risk event. The key mismatch is functional: Mean time to repair (MTTR) addresses the average time needed to restore a failed component or service, the need stated by the question.

Answer D is incorrect because Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time. That concept can be valid in another scenario, but this question is testing the average time needed to restore a failed component or service; Mean time to repair (MTTR) therefore fits the requirement more directly.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!