CompTIA Security+ SY0-701 Risk Management Practice Test
Topic 24 focuses on Risk Management for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
Which process of recognizing threats, vulnerabilities, assets, scenarios, and consequences could affect objectives?
Correct Answer: B
Correct Answer
Answer B is correct because Risk identification means the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives.
Incorrect Answers
Answer A is incorrect because Single loss expectancy (SLE) addresses a different requirement. Single loss expectancy (SLE) refers to the expected financial loss from one occurrence of a risk event.
Answer C is incorrect because Mean time to repair (MTTR) represents a different security function. Mean time to repair (MTTR) refers to the average time needed to restore a failed component or service.
Answer D is incorrect because Recurring risk assessment would fit a different scenario. Recurring risk assessment refers to a risk review performed on a defined schedule.
Question 2
To re-evaluate risk as systems, threats, and business conditions change, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Recurring risk assessment means a risk review performed on a defined schedule.
Incorrect Answers
Answer A is incorrect because Mean time to repair (MTTR) addresses a different security requirement. Mean time to repair (MTTR) refers to the average time needed to restore a failed component or service.
Answer B is incorrect because Recovery time objective (RTO) addresses a different requirement. Recovery time objective (RTO) refers to the target maximum time a service or process should remain unavailable after disruption.
Answer C is incorrect because Risk avoidance would fit a different scenario. Risk avoidance refers to a treatment strategy that eliminates the activity or condition creating the risk.
Question 3
Which term describes ongoing or frequently updated assessment using current data and events?
Correct Answer: C
Correct Answer
Answer C is correct because Continuous risk assessment means ongoing or frequently updated assessment using current data and events.
Incorrect Answers
Answer A is incorrect because Recovery point objective (RPO) represents a different security function. Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time.
Answer B is incorrect because Qualitative risk analysis addresses a different requirement. Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high.
Answer D is incorrect because Risk avoidance would fit a different scenario. Risk avoidance refers to a treatment strategy that eliminates the activity or condition creating the risk.
Question 4
To compare risks when precise monetary data is unavailable or unnecessary, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Qualitative risk analysis means risk analysis using descriptive or ordinal ratings such as low, medium, and high.
Incorrect Answers
Answer A is incorrect because Risk threshold addresses a different requirement. Risk threshold refers to a defined level at which a risk or indicator requires escalation or action.
Answer B is incorrect because Recurring risk assessment would fit a different scenario. Recurring risk assessment refers to a risk review performed on a defined schedule.
Answer D is incorrect because Quantitative risk analysis addresses a different security requirement. Quantitative risk analysis refers to risk analysis using numerical probabilities and financial or measurable impact values.
Question 5
Which term describes risk analysis using numerical probabilities and financial or measurable impact values?
Correct Answer: B
Correct Answer
Answer B is correct because Quantitative risk analysis means risk analysis using numerical probabilities and financial or measurable impact values.
Incorrect Answers
Answer A is incorrect because Risk threshold addresses a different requirement. Risk threshold refers to a defined level at which a risk or indicator requires escalation or action.
Answer C is incorrect because Risk owner represents a different security function. Risk owner refers to the individual or role accountable for monitoring and making decisions about a specific risk.
Answer D is incorrect because Recovery point objective (RPO) would fit a different scenario. Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time.
Question 6
To estimate the monetary impact of a single incident, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Single loss expectancy (SLE) means the expected financial loss from one occurrence of a risk event.
Incorrect Answers
Answer A is incorrect because Recovery point objective (RPO) addresses a different security requirement. Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time.
Answer C is incorrect because Risk appetite addresses a different requirement. Risk appetite refers to the overall amount and type of risk an organization is willing to pursue or retain.
Answer D is incorrect because Qualitative risk analysis would fit a different scenario. Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high.
Question 7
What is the expected frequency of a risk event within one year?
Correct Answer: A
Correct Answer
Answer A is correct because Annualized rate of occurrence (ARO) means the expected frequency of a risk event within one year.
Incorrect Answers
Answer B is incorrect because Recurring risk assessment addresses a different requirement. Recurring risk assessment refers to a risk review performed on a defined schedule.
Answer C is incorrect because Risk owner represents a different security function. Risk owner refers to the individual or role accountable for monitoring and making decisions about a specific risk.
Answer D is incorrect because Key risk indicator (KRI) would fit a different scenario. Key risk indicator (KRI) refers to a metric used to signal changes in risk exposure or conditions.
Question 8
To compare annualized financial exposure across risks, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Annualized loss expectancy (ALE) means the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.
Incorrect Answers
Answer A is incorrect because Continuous risk assessment would fit a different scenario. Continuous risk assessment refers to ongoing or frequently updated assessment using current data and events.
Answer B is incorrect because Risk appetite addresses a different requirement. Risk appetite refers to the overall amount and type of risk an organization is willing to pursue or retain.
Answer C is incorrect because Risk acceptance addresses a different security requirement. Risk acceptance refers to a treatment decision to knowingly retain a risk within approved tolerance.
Question 9
What is the estimated percentage of asset value lost in one event?
Correct Answer: A
Correct Answer
Answer A is correct because Exposure factor means the estimated percentage of asset value lost in one event.
Incorrect Answers
Answer B is incorrect because Recovery time objective (RTO) represents a different security function. Recovery time objective (RTO) refers to the target maximum time a service or process should remain unavailable after disruption.
Answer C is incorrect because Risk mitigation would fit a different scenario. Risk mitigation refers to a treatment strategy that reduces likelihood or impact through controls.
Answer D is incorrect because Mean time between failures (MTBF) addresses a different requirement. Mean time between failures (MTBF) refers to the average operating time between failures for a repairable component or system.
Question 10
To track risk decisions and accountability over time, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Risk register means a maintained record of identified risks, ratings, owners, responses, and status.
Incorrect Answers
Answer B is incorrect because Qualitative risk analysis addresses a different security requirement. Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high.
Answer C is incorrect because Recurring risk assessment addresses a different requirement. Recurring risk assessment refers to a risk review performed on a defined schedule.
Answer D is incorrect because Single loss expectancy (SLE) would fit a different scenario. Single loss expectancy (SLE) refers to the expected financial loss from one occurrence of a risk event.
Question 11
Which metric is used to signal changes in risk exposure or conditions?
Correct Answer: B
Correct Answer
Answer B is correct because Key risk indicator (KRI) means a metric used to signal changes in risk exposure or conditions.
Incorrect Answers
Answer A is incorrect because Recovery time objective (RTO) would fit a different scenario. Recovery time objective (RTO) refers to the target maximum time a service or process should remain unavailable after disruption.
Answer C is incorrect because Risk mitigation addresses a different requirement. Risk mitigation refers to a treatment strategy that reduces likelihood or impact through controls.
Answer D is incorrect because Business impact analysis (BIA) represents a different security function. Business impact analysis (BIA) refers to analysis of critical processes, dependencies, and consequences of disruption.
Question 12
To ensure someone has responsibility for treatment and acceptance decisions, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Risk owner means the individual or role accountable for monitoring and making decisions about a specific risk.
Incorrect Answers
Answer B is incorrect because Annualized rate of occurrence (ARO) addresses a different requirement. Annualized rate of occurrence (ARO) refers to the expected frequency of a risk event within one year.
Answer C is incorrect because Mean time to repair (MTTR) addresses a different security requirement. Mean time to repair (MTTR) refers to the average time needed to restore a failed component or service.
Answer D is incorrect because Risk transfer would fit a different scenario. Risk transfer refers to a treatment strategy that shifts some financial or operational consequence to another party.
Question 13
What is a defined level at which a risk or indicator requires escalation or action?
Correct Answer: A
Correct Answer
Answer A is correct because Risk threshold means a defined level at which a risk or indicator requires escalation or action.
Incorrect Answers
Answer B is incorrect because Annualized loss expectancy (ALE) represents a different security function. Annualized loss expectancy (ALE) refers to the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.
Answer C is incorrect because Qualitative risk analysis would fit a different scenario. Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high.
Answer D is incorrect because Exposure factor addresses a different requirement. Exposure factor refers to the estimated percentage of asset value lost in one event.
Question 14
To define how much risk the organization is prepared to bear in a specific context, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Risk tolerance means the acceptable amount of variation or exposure around objectives.
Incorrect Answers
Answer A is incorrect because Qualitative risk analysis addresses a different security requirement. Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high.
Answer B is incorrect because Annualized loss expectancy (ALE) addresses a different requirement. Annualized loss expectancy (ALE) refers to the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.
Answer C is incorrect because Risk register would fit a different scenario. Risk register refers to a maintained record of identified risks, ratings, owners, responses, and status.
Question 15
What is the overall amount and type of risk an organization is willing to pursue or retain?
Correct Answer: C
Correct Answer
Answer C is correct because Risk appetite means the overall amount and type of risk an organization is willing to pursue or retain.
Incorrect Answers
Answer A is incorrect because Mean time to repair (MTTR) represents a different security function. Mean time to repair (MTTR) refers to the average time needed to restore a failed component or service.
Answer B is incorrect because Business impact analysis (BIA) would fit a different scenario. Business impact analysis (BIA) refers to analysis of critical processes, dependencies, and consequences of disruption.
Answer D is incorrect because Exposure factor addresses a different requirement. Exposure factor refers to the estimated percentage of asset value lost in one event.
Question 16
To use insurance or contracts to redistribute defined impacts, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Risk transfer means a treatment strategy that shifts some financial or operational consequence to another party.
Incorrect Answers
Answer B is incorrect because Recurring risk assessment would fit a different scenario. Recurring risk assessment refers to a risk review performed on a defined schedule.
Answer C is incorrect because Risk identification addresses a different security requirement. Risk identification refers to the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives.
Answer D is incorrect because Recovery time objective (RTO) addresses a different requirement. Recovery time objective (RTO) refers to the target maximum time a service or process should remain unavailable after disruption.
Question 17
What is a treatment decision to knowingly retain a risk within approved tolerance?
Correct Answer: D
Correct Answer
Answer D is correct because Risk acceptance means a treatment decision to knowingly retain a risk within approved tolerance.
Incorrect Answers
Answer A is incorrect because Risk identification would fit a different scenario. Risk identification refers to the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives.
Answer B is incorrect because Annualized rate of occurrence (ARO) addresses a different requirement. Annualized rate of occurrence (ARO) refers to the expected frequency of a risk event within one year.
Answer C is incorrect because Recovery point objective (RPO) represents a different security function. Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time.
Question 18
To remove exposure by not performing the risky activity, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Risk avoidance means a treatment strategy that eliminates the activity or condition creating the risk.
Incorrect Answers
Answer B is incorrect because Quantitative risk analysis addresses a different requirement. Quantitative risk analysis refers to risk analysis using numerical probabilities and financial or measurable impact values.
Answer C is incorrect because Mean time between failures (MTBF) addresses a different security requirement. Mean time between failures (MTBF) refers to the average operating time between failures for a repairable component or system.
Answer D is incorrect because Key risk indicator (KRI) would fit a different scenario. Key risk indicator (KRI) refers to a metric used to signal changes in risk exposure or conditions.
Question 19
Which treatment strategy reduces likelihood or impact through controls?
Correct Answer: B
Correct Answer
Answer B is correct because Risk mitigation means a treatment strategy that reduces likelihood or impact through controls.
Incorrect Answers
Answer A is incorrect because Quantitative risk analysis represents a different security function. Quantitative risk analysis refers to risk analysis using numerical probabilities and financial or measurable impact values.
Answer C is incorrect because Risk avoidance addresses a different requirement. Risk avoidance refers to a treatment strategy that eliminates the activity or condition creating the risk.
Answer D is incorrect because Recurring risk assessment would fit a different scenario. Recurring risk assessment refers to a risk review performed on a defined schedule.
Question 20
To set recovery priorities and objectives based on business impact, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Business impact analysis (BIA) means analysis of critical processes, dependencies, and consequences of disruption.
Incorrect Answers
Answer A is incorrect because Risk register addresses a different security requirement. Risk register refers to a maintained record of identified risks, ratings, owners, responses, and status.
Answer B is incorrect because Annualized loss expectancy (ALE) addresses a different requirement. Annualized loss expectancy (ALE) refers to the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.
Answer D is incorrect because Recurring risk assessment would fit a different scenario. Recurring risk assessment refers to a risk review performed on a defined schedule.
Question 21
What is the target maximum time a service or process should remain unavailable after disruption?
Correct Answer: C
Correct Answer
Answer C is correct because Recovery time objective (RTO) means the target maximum time a service or process should remain unavailable after disruption.
Incorrect Answers
Answer A is incorrect because Recovery point objective (RPO) addresses a different requirement. Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time.
Answer B is incorrect because Annualized loss expectancy (ALE) represents a different security function. Annualized loss expectancy (ALE) refers to the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.
Answer D is incorrect because Single loss expectancy (SLE) would fit a different scenario. Single loss expectancy (SLE) refers to the expected financial loss from one occurrence of a risk event.
Question 22
To determine how current recovered data must be, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Recovery point objective (RPO) means the target maximum acceptable amount of data loss measured backward in time.
Incorrect Answers
Answer B is incorrect because Quantitative risk analysis addresses a different security requirement. Quantitative risk analysis refers to risk analysis using numerical probabilities and financial or measurable impact values.
Answer C is incorrect because Risk mitigation addresses a different requirement. Risk mitigation refers to a treatment strategy that reduces likelihood or impact through controls.
Answer D is incorrect because Risk appetite would fit a different scenario. Risk appetite refers to the overall amount and type of risk an organization is willing to pursue or retain.
Question 23
What is the average time needed to restore a failed component or service?
Correct Answer: D
Correct Answer
Answer D is correct because Mean time to repair (MTTR) means the average time needed to restore a failed component or service.
Incorrect Answers
Answer A is incorrect because Single loss expectancy (SLE) would fit a different scenario. Single loss expectancy (SLE) refers to the expected financial loss from one occurrence of a risk event.
Answer B is incorrect because Risk avoidance addresses a different requirement. Risk avoidance refers to a treatment strategy that eliminates the activity or condition creating the risk.
Answer C is incorrect because Recovery point objective (RPO) represents a different security function. Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time.
Question 24
To estimate reliability and expected failure frequency, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Mean time between failures (MTBF) means the average operating time between failures for a repairable component or system.
Incorrect Answers
Answer A is incorrect because Risk tolerance addresses a different requirement. Risk tolerance refers to the acceptable amount of variation or exposure around objectives.
Answer C is incorrect because Business impact analysis (BIA) addresses a different security requirement. Business impact analysis (BIA) refers to analysis of critical processes, dependencies, and consequences of disruption.
Answer D is incorrect because Annualized rate of occurrence (ARO) would fit a different scenario. Annualized rate of occurrence (ARO) refers to the expected frequency of a risk event within one year.
Question 25
To create the set of risks that need analysis and treatment, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Risk identification means the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives.
Incorrect Answers
Answer A is incorrect because Risk tolerance represents a different security function. Risk tolerance refers to the acceptable amount of variation or exposure around objectives.
Answer B is incorrect because Risk appetite would fit a different scenario. Risk appetite refers to the overall amount and type of risk an organization is willing to pursue or retain.
Answer D is incorrect because Qualitative risk analysis addresses a different security requirement. Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high.
Question 26
Which risk review is performed on a defined schedule?
Correct Answer: D
Correct Answer
Answer D is correct because Recurring risk assessment means a risk review performed on a defined schedule.
Incorrect Answers
Answer A is incorrect because Risk owner addresses a different requirement. Risk owner refers to the individual or role accountable for monitoring and making decisions about a specific risk.
Answer B is incorrect because Business impact analysis (BIA) addresses a different security requirement. Business impact analysis (BIA) refers to analysis of critical processes, dependencies, and consequences of disruption.
Answer C is incorrect because Risk register represents a different security function. Risk register refers to a maintained record of identified risks, ratings, owners, responses, and status.
Question 27
To adapt risk understanding dynamically rather than only at periodic checkpoints, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Continuous risk assessment means ongoing or frequently updated assessment using current data and events.
Incorrect Answers
Answer B is incorrect because Risk transfer would fit a different scenario. Risk transfer refers to a treatment strategy that shifts some financial or operational consequence to another party.
Answer C is incorrect because Exposure factor represents a different security function. Exposure factor refers to the estimated percentage of asset value lost in one event.
Answer D is incorrect because Risk threshold addresses a different security requirement. Risk threshold refers to a defined level at which a risk or indicator requires escalation or action.
Question 28
Which term describes risk analysis using descriptive or ordinal ratings such as low, medium, and high?
Correct Answer: B
Correct Answer
Answer B is correct because Qualitative risk analysis means risk analysis using descriptive or ordinal ratings such as low, medium, and high.
Incorrect Answers
Answer A is incorrect because Risk avoidance addresses a different security requirement. Risk avoidance refers to a treatment strategy that eliminates the activity or condition creating the risk.
Answer C is incorrect because Risk tolerance addresses a different requirement. Risk tolerance refers to the acceptable amount of variation or exposure around objectives.
Answer D is incorrect because Quantitative risk analysis represents a different security function. Quantitative risk analysis refers to risk analysis using numerical probabilities and financial or measurable impact values.
Question 29
To estimate expected losses and support cost-benefit decisions, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Quantitative risk analysis means risk analysis using numerical probabilities and financial or measurable impact values.
Incorrect Answers
Answer A is incorrect because Risk owner addresses a different security requirement. Risk owner refers to the individual or role accountable for monitoring and making decisions about a specific risk.
Answer B is incorrect because Single loss expectancy (SLE) represents a different security function. Single loss expectancy (SLE) refers to the expected financial loss from one occurrence of a risk event.
Answer C is incorrect because Recurring risk assessment would fit a different scenario. Recurring risk assessment refers to a risk review performed on a defined schedule.
Question 30
What is the expected financial loss from one occurrence of a risk event?
Correct Answer: D
Correct Answer
Answer D is correct because Single loss expectancy (SLE) means the expected financial loss from one occurrence of a risk event.
Incorrect Answers
Answer A is incorrect because Risk mitigation addresses a different requirement. Risk mitigation refers to a treatment strategy that reduces likelihood or impact through controls.
Answer B is incorrect because Annualized loss expectancy (ALE) addresses a different security requirement. Annualized loss expectancy (ALE) refers to the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.
Answer C is incorrect because Risk identification represents a different security function. Risk identification refers to the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives.
Question 31
To convert event likelihood into an annual frequency estimate, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Annualized rate of occurrence (ARO) means the expected frequency of a risk event within one year.
Incorrect Answers
Answer A is incorrect because Risk transfer addresses a different security requirement. Risk transfer refers to a treatment strategy that shifts some financial or operational consequence to another party.
Answer C is incorrect because Risk register represents a different security function. Risk register refers to a maintained record of identified risks, ratings, owners, responses, and status.
Answer D is incorrect because Quantitative risk analysis would fit a different scenario. Quantitative risk analysis refers to risk analysis using numerical probabilities and financial or measurable impact values.
Question 32
What is the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO?
Correct Answer: B
Correct Answer
Answer B is correct because Annualized loss expectancy (ALE) means the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.
Incorrect Answers
Answer A is incorrect because Risk identification represents a different security function. Risk identification refers to the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives.
Answer C is incorrect because Qualitative risk analysis addresses a different security requirement. Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high.
Answer D is incorrect because Key risk indicator (KRI) addresses a different requirement. Key risk indicator (KRI) refers to a metric used to signal changes in risk exposure or conditions.
Question 33
To calculate the loss portion used in quantitative risk analysis, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Exposure factor means the estimated percentage of asset value lost in one event.
Incorrect Answers
Answer A is incorrect because Risk threshold addresses a different security requirement. Risk threshold refers to a defined level at which a risk or indicator requires escalation or action.
Answer B is incorrect because Annualized loss expectancy (ALE) would fit a different scenario. Annualized loss expectancy (ALE) refers to the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.
Answer D is incorrect because Business impact analysis (BIA) represents a different security function. Business impact analysis (BIA) refers to analysis of critical processes, dependencies, and consequences of disruption.
Question 34
What is a maintained record of identified risks, ratings, owners, responses, and status?
Correct Answer: C
Correct Answer
Answer C is correct because Risk register means a maintained record of identified risks, ratings, owners, responses, and status.
Incorrect Answers
Answer A is incorrect because Risk identification represents a different security function. Risk identification refers to the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives.
Answer B is incorrect because Key risk indicator (KRI) addresses a different requirement. Key risk indicator (KRI) refers to a metric used to signal changes in risk exposure or conditions.
Answer D is incorrect because Continuous risk assessment addresses a different security requirement. Continuous risk assessment refers to ongoing or frequently updated assessment using current data and events.
Question 35
To provide early warning that risk may be increasing or controls may be weakening, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Key risk indicator (KRI) means a metric used to signal changes in risk exposure or conditions.
Incorrect Answers
Answer A is incorrect because Mean time to repair (MTTR) would fit a different scenario. Mean time to repair (MTTR) refers to the average time needed to restore a failed component or service.
Answer B is incorrect because Risk acceptance represents a different security function. Risk acceptance refers to a treatment decision to knowingly retain a risk within approved tolerance.
Answer D is incorrect because Risk appetite addresses a different security requirement. Risk appetite refers to the overall amount and type of risk an organization is willing to pursue or retain.
Popular posts
Recent Posts
