CompTIA Security+ SY0-701 Risk Management Practice Test

 

Topic 24 focuses on Risk Management for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

Which process of recognizing threats, vulnerabilities, assets, scenarios, and consequences could affect objectives?

  1. Single loss expectancy (SLE)
  2. Risk identification
  3. Mean time to repair (MTTR)
  4. Recurring risk assessment

Correct Answer: B

 

Correct Answer

Answer B is correct because Risk identification means the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives.

Incorrect Answers

Answer A is incorrect because Single loss expectancy (SLE) addresses a different requirement. Single loss expectancy (SLE) refers to the expected financial loss from one occurrence of a risk event.

Answer C is incorrect because Mean time to repair (MTTR) represents a different security function. Mean time to repair (MTTR) refers to the average time needed to restore a failed component or service.

Answer D is incorrect because Recurring risk assessment would fit a different scenario. Recurring risk assessment refers to a risk review performed on a defined schedule.

 

Question 2

To re-evaluate risk as systems, threats, and business conditions change, which security approach should be selected?

  1. Mean time to repair (MTTR)
  2. Recovery time objective (RTO)
  3. Risk avoidance
  4. Recurring risk assessment

Correct Answer: D

 

Correct Answer

Answer D is correct because Recurring risk assessment means a risk review performed on a defined schedule.

Incorrect Answers

Answer A is incorrect because Mean time to repair (MTTR) addresses a different security requirement. Mean time to repair (MTTR) refers to the average time needed to restore a failed component or service.

Answer B is incorrect because Recovery time objective (RTO) addresses a different requirement. Recovery time objective (RTO) refers to the target maximum time a service or process should remain unavailable after disruption.

Answer C is incorrect because Risk avoidance would fit a different scenario. Risk avoidance refers to a treatment strategy that eliminates the activity or condition creating the risk.

 

Question 3

Which term describes ongoing or frequently updated assessment using current data and events?

  1. Recovery point objective (RPO)
  2. Qualitative risk analysis
  3. Continuous risk assessment
  4. Risk avoidance

Correct Answer: C

 

Correct Answer

Answer C is correct because Continuous risk assessment means ongoing or frequently updated assessment using current data and events.

Incorrect Answers

Answer A is incorrect because Recovery point objective (RPO) represents a different security function. Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time.

Answer B is incorrect because Qualitative risk analysis addresses a different requirement. Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high.

Answer D is incorrect because Risk avoidance would fit a different scenario. Risk avoidance refers to a treatment strategy that eliminates the activity or condition creating the risk.

 

Question 4

To compare risks when precise monetary data is unavailable or unnecessary, which security approach should be selected?

  1. Risk threshold
  2. Recurring risk assessment
  3. Qualitative risk analysis
  4. Quantitative risk analysis

Correct Answer: C

 

Correct Answer

Answer C is correct because Qualitative risk analysis means risk analysis using descriptive or ordinal ratings such as low, medium, and high.

Incorrect Answers

Answer A is incorrect because Risk threshold addresses a different requirement. Risk threshold refers to a defined level at which a risk or indicator requires escalation or action.

Answer B is incorrect because Recurring risk assessment would fit a different scenario. Recurring risk assessment refers to a risk review performed on a defined schedule.

Answer D is incorrect because Quantitative risk analysis addresses a different security requirement. Quantitative risk analysis refers to risk analysis using numerical probabilities and financial or measurable impact values.

 

Question 5

Which term describes risk analysis using numerical probabilities and financial or measurable impact values?

  1. Risk threshold
  2. Quantitative risk analysis
  3. Risk owner
  4. Recovery point objective (RPO)

Correct Answer: B

 

Correct Answer

Answer B is correct because Quantitative risk analysis means risk analysis using numerical probabilities and financial or measurable impact values.

Incorrect Answers

Answer A is incorrect because Risk threshold addresses a different requirement. Risk threshold refers to a defined level at which a risk or indicator requires escalation or action.

Answer C is incorrect because Risk owner represents a different security function. Risk owner refers to the individual or role accountable for monitoring and making decisions about a specific risk.

Answer D is incorrect because Recovery point objective (RPO) would fit a different scenario. Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time.

 

Question 6

To estimate the monetary impact of a single incident, which security approach should be selected?

  1. Recovery point objective (RPO)
  2. Single loss expectancy (SLE)
  3. Risk appetite
  4. Qualitative risk analysis

Correct Answer: B

 

Correct Answer

Answer B is correct because Single loss expectancy (SLE) means the expected financial loss from one occurrence of a risk event.

Incorrect Answers

Answer A is incorrect because Recovery point objective (RPO) addresses a different security requirement. Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time.

Answer C is incorrect because Risk appetite addresses a different requirement. Risk appetite refers to the overall amount and type of risk an organization is willing to pursue or retain.

Answer D is incorrect because Qualitative risk analysis would fit a different scenario. Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high.

 

Question 7

What is the expected frequency of a risk event within one year?

  1. Annualized rate of occurrence (ARO)
  2. Recurring risk assessment
  3. Risk owner
  4. Key risk indicator (KRI)

Correct Answer: A

 

Correct Answer

Answer A is correct because Annualized rate of occurrence (ARO) means the expected frequency of a risk event within one year.

Incorrect Answers

Answer B is incorrect because Recurring risk assessment addresses a different requirement. Recurring risk assessment refers to a risk review performed on a defined schedule.

Answer C is incorrect because Risk owner represents a different security function. Risk owner refers to the individual or role accountable for monitoring and making decisions about a specific risk.

Answer D is incorrect because Key risk indicator (KRI) would fit a different scenario. Key risk indicator (KRI) refers to a metric used to signal changes in risk exposure or conditions.

 

Question 8

To compare annualized financial exposure across risks, which security approach should be selected?

  1. Continuous risk assessment
  2. Risk appetite
  3. Risk acceptance
  4. Annualized loss expectancy (ALE)

Correct Answer: D

 

Correct Answer

Answer D is correct because Annualized loss expectancy (ALE) means the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.

Incorrect Answers

Answer A is incorrect because Continuous risk assessment would fit a different scenario. Continuous risk assessment refers to ongoing or frequently updated assessment using current data and events.

Answer B is incorrect because Risk appetite addresses a different requirement. Risk appetite refers to the overall amount and type of risk an organization is willing to pursue or retain.

Answer C is incorrect because Risk acceptance addresses a different security requirement. Risk acceptance refers to a treatment decision to knowingly retain a risk within approved tolerance.

 

Question 9

What is the estimated percentage of asset value lost in one event?

  1. Exposure factor
  2. Recovery time objective (RTO)
  3. Risk mitigation
  4. Mean time between failures (MTBF)

Correct Answer: A

 

Correct Answer

Answer A is correct because Exposure factor means the estimated percentage of asset value lost in one event.

Incorrect Answers

Answer B is incorrect because Recovery time objective (RTO) represents a different security function. Recovery time objective (RTO) refers to the target maximum time a service or process should remain unavailable after disruption.

Answer C is incorrect because Risk mitigation would fit a different scenario. Risk mitigation refers to a treatment strategy that reduces likelihood or impact through controls.

Answer D is incorrect because Mean time between failures (MTBF) addresses a different requirement. Mean time between failures (MTBF) refers to the average operating time between failures for a repairable component or system.

 

Question 10

To track risk decisions and accountability over time, which security approach should be selected?

  1. Risk register
  2. Qualitative risk analysis
  3. Recurring risk assessment
  4. Single loss expectancy (SLE)

Correct Answer: A

 

Correct Answer

Answer A is correct because Risk register means a maintained record of identified risks, ratings, owners, responses, and status.

Incorrect Answers

Answer B is incorrect because Qualitative risk analysis addresses a different security requirement. Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high.

Answer C is incorrect because Recurring risk assessment addresses a different requirement. Recurring risk assessment refers to a risk review performed on a defined schedule.

Answer D is incorrect because Single loss expectancy (SLE) would fit a different scenario. Single loss expectancy (SLE) refers to the expected financial loss from one occurrence of a risk event.

 

Question 11

Which metric is used to signal changes in risk exposure or conditions?

  1. Recovery time objective (RTO)
  2. Key risk indicator (KRI)
  3. Risk mitigation
  4. Business impact analysis (BIA)

Correct Answer: B

 

Correct Answer

Answer B is correct because Key risk indicator (KRI) means a metric used to signal changes in risk exposure or conditions.

Incorrect Answers

Answer A is incorrect because Recovery time objective (RTO) would fit a different scenario. Recovery time objective (RTO) refers to the target maximum time a service or process should remain unavailable after disruption.

Answer C is incorrect because Risk mitigation addresses a different requirement. Risk mitigation refers to a treatment strategy that reduces likelihood or impact through controls.

Answer D is incorrect because Business impact analysis (BIA) represents a different security function. Business impact analysis (BIA) refers to analysis of critical processes, dependencies, and consequences of disruption.

 

Question 12

To ensure someone has responsibility for treatment and acceptance decisions, which security approach should be selected?

  1. Risk owner
  2. Annualized rate of occurrence (ARO)
  3. Mean time to repair (MTTR)
  4. Risk transfer

Correct Answer: A

 

Correct Answer

Answer A is correct because Risk owner means the individual or role accountable for monitoring and making decisions about a specific risk.

Incorrect Answers

Answer B is incorrect because Annualized rate of occurrence (ARO) addresses a different requirement. Annualized rate of occurrence (ARO) refers to the expected frequency of a risk event within one year.

Answer C is incorrect because Mean time to repair (MTTR) addresses a different security requirement. Mean time to repair (MTTR) refers to the average time needed to restore a failed component or service.

Answer D is incorrect because Risk transfer would fit a different scenario. Risk transfer refers to a treatment strategy that shifts some financial or operational consequence to another party.

 

Question 13

What is a defined level at which a risk or indicator requires escalation or action?

  1. Risk threshold
  2. Annualized loss expectancy (ALE)
  3. Qualitative risk analysis
  4. Exposure factor

Correct Answer: A

 

Correct Answer

Answer A is correct because Risk threshold means a defined level at which a risk or indicator requires escalation or action.

Incorrect Answers

Answer B is incorrect because Annualized loss expectancy (ALE) represents a different security function. Annualized loss expectancy (ALE) refers to the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.

Answer C is incorrect because Qualitative risk analysis would fit a different scenario. Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high.

Answer D is incorrect because Exposure factor addresses a different requirement. Exposure factor refers to the estimated percentage of asset value lost in one event.

 

Question 14

To define how much risk the organization is prepared to bear in a specific context, which security approach should be selected?

  1. Qualitative risk analysis
  2. Annualized loss expectancy (ALE)
  3. Risk register
  4. Risk tolerance

Correct Answer: D

 

Correct Answer

Answer D is correct because Risk tolerance means the acceptable amount of variation or exposure around objectives.

Incorrect Answers

Answer A is incorrect because Qualitative risk analysis addresses a different security requirement. Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high.

Answer B is incorrect because Annualized loss expectancy (ALE) addresses a different requirement. Annualized loss expectancy (ALE) refers to the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.

Answer C is incorrect because Risk register would fit a different scenario. Risk register refers to a maintained record of identified risks, ratings, owners, responses, and status.

 

Question 15

What is the overall amount and type of risk an organization is willing to pursue or retain?

  1. Mean time to repair (MTTR)
  2. Business impact analysis (BIA)
  3. Risk appetite
  4. Exposure factor

Correct Answer: C

 

Correct Answer

Answer C is correct because Risk appetite means the overall amount and type of risk an organization is willing to pursue or retain.

Incorrect Answers

Answer A is incorrect because Mean time to repair (MTTR) represents a different security function. Mean time to repair (MTTR) refers to the average time needed to restore a failed component or service.

Answer B is incorrect because Business impact analysis (BIA) would fit a different scenario. Business impact analysis (BIA) refers to analysis of critical processes, dependencies, and consequences of disruption.

Answer D is incorrect because Exposure factor addresses a different requirement. Exposure factor refers to the estimated percentage of asset value lost in one event.

 

Question 16

To use insurance or contracts to redistribute defined impacts, which security approach should be selected?

  1. Risk transfer
  2. Recurring risk assessment
  3. Risk identification
  4. Recovery time objective (RTO)

Correct Answer: A

 

Correct Answer

Answer A is correct because Risk transfer means a treatment strategy that shifts some financial or operational consequence to another party.

Incorrect Answers

Answer B is incorrect because Recurring risk assessment would fit a different scenario. Recurring risk assessment refers to a risk review performed on a defined schedule.

Answer C is incorrect because Risk identification addresses a different security requirement. Risk identification refers to the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives.

Answer D is incorrect because Recovery time objective (RTO) addresses a different requirement. Recovery time objective (RTO) refers to the target maximum time a service or process should remain unavailable after disruption.

 

Question 17

What is a treatment decision to knowingly retain a risk within approved tolerance?

  1. Risk identification
  2. Annualized rate of occurrence (ARO)
  3. Recovery point objective (RPO)
  4. Risk acceptance

Correct Answer: D

 

Correct Answer

Answer D is correct because Risk acceptance means a treatment decision to knowingly retain a risk within approved tolerance.

Incorrect Answers

Answer A is incorrect because Risk identification would fit a different scenario. Risk identification refers to the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives.

Answer B is incorrect because Annualized rate of occurrence (ARO) addresses a different requirement. Annualized rate of occurrence (ARO) refers to the expected frequency of a risk event within one year.

Answer C is incorrect because Recovery point objective (RPO) represents a different security function. Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time.

 

Question 18

To remove exposure by not performing the risky activity, which security approach should be selected?

  1. Risk avoidance
  2. Quantitative risk analysis
  3. Mean time between failures (MTBF)
  4. Key risk indicator (KRI)

Correct Answer: A

 

Correct Answer

Answer A is correct because Risk avoidance means a treatment strategy that eliminates the activity or condition creating the risk.

Incorrect Answers

Answer B is incorrect because Quantitative risk analysis addresses a different requirement. Quantitative risk analysis refers to risk analysis using numerical probabilities and financial or measurable impact values.

Answer C is incorrect because Mean time between failures (MTBF) addresses a different security requirement. Mean time between failures (MTBF) refers to the average operating time between failures for a repairable component or system.

Answer D is incorrect because Key risk indicator (KRI) would fit a different scenario. Key risk indicator (KRI) refers to a metric used to signal changes in risk exposure or conditions.

 

Question 19

Which treatment strategy reduces likelihood or impact through controls?

  1. Quantitative risk analysis
  2. Risk mitigation
  3. Risk avoidance
  4. Recurring risk assessment

Correct Answer: B

 

Correct Answer

Answer B is correct because Risk mitigation means a treatment strategy that reduces likelihood or impact through controls.

Incorrect Answers

Answer A is incorrect because Quantitative risk analysis represents a different security function. Quantitative risk analysis refers to risk analysis using numerical probabilities and financial or measurable impact values.

Answer C is incorrect because Risk avoidance addresses a different requirement. Risk avoidance refers to a treatment strategy that eliminates the activity or condition creating the risk.

Answer D is incorrect because Recurring risk assessment would fit a different scenario. Recurring risk assessment refers to a risk review performed on a defined schedule.

 

Question 20

To set recovery priorities and objectives based on business impact, which security approach should be selected?

  1. Risk register
  2. Annualized loss expectancy (ALE)
  3. Business impact analysis (BIA)
  4. Recurring risk assessment

Correct Answer: C

 

Correct Answer

Answer C is correct because Business impact analysis (BIA) means analysis of critical processes, dependencies, and consequences of disruption.

Incorrect Answers

Answer A is incorrect because Risk register addresses a different security requirement. Risk register refers to a maintained record of identified risks, ratings, owners, responses, and status.

Answer B is incorrect because Annualized loss expectancy (ALE) addresses a different requirement. Annualized loss expectancy (ALE) refers to the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.

Answer D is incorrect because Recurring risk assessment would fit a different scenario. Recurring risk assessment refers to a risk review performed on a defined schedule.

 

Question 21

What is the target maximum time a service or process should remain unavailable after disruption?

  1. Recovery point objective (RPO)
  2. Annualized loss expectancy (ALE)
  3. Recovery time objective (RTO)
  4. Single loss expectancy (SLE)

Correct Answer: C

 

Correct Answer

Answer C is correct because Recovery time objective (RTO) means the target maximum time a service or process should remain unavailable after disruption.

Incorrect Answers

Answer A is incorrect because Recovery point objective (RPO) addresses a different requirement. Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time.

Answer B is incorrect because Annualized loss expectancy (ALE) represents a different security function. Annualized loss expectancy (ALE) refers to the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.

Answer D is incorrect because Single loss expectancy (SLE) would fit a different scenario. Single loss expectancy (SLE) refers to the expected financial loss from one occurrence of a risk event.

 

Question 22

To determine how current recovered data must be, which security approach should be selected?

  1. Recovery point objective (RPO)
  2. Quantitative risk analysis
  3. Risk mitigation
  4. Risk appetite

Correct Answer: A

 

Correct Answer

Answer A is correct because Recovery point objective (RPO) means the target maximum acceptable amount of data loss measured backward in time.

Incorrect Answers

Answer B is incorrect because Quantitative risk analysis addresses a different security requirement. Quantitative risk analysis refers to risk analysis using numerical probabilities and financial or measurable impact values.

Answer C is incorrect because Risk mitigation addresses a different requirement. Risk mitigation refers to a treatment strategy that reduces likelihood or impact through controls.

Answer D is incorrect because Risk appetite would fit a different scenario. Risk appetite refers to the overall amount and type of risk an organization is willing to pursue or retain.

 

Question 23

What is the average time needed to restore a failed component or service?

  1. Single loss expectancy (SLE)
  2. Risk avoidance
  3. Recovery point objective (RPO)
  4. Mean time to repair (MTTR)

Correct Answer: D

 

Correct Answer

Answer D is correct because Mean time to repair (MTTR) means the average time needed to restore a failed component or service.

Incorrect Answers

Answer A is incorrect because Single loss expectancy (SLE) would fit a different scenario. Single loss expectancy (SLE) refers to the expected financial loss from one occurrence of a risk event.

Answer B is incorrect because Risk avoidance addresses a different requirement. Risk avoidance refers to a treatment strategy that eliminates the activity or condition creating the risk.

Answer C is incorrect because Recovery point objective (RPO) represents a different security function. Recovery point objective (RPO) refers to the target maximum acceptable amount of data loss measured backward in time.

 

Question 24

To estimate reliability and expected failure frequency, which security approach should be selected?

  1. Risk tolerance
  2. Mean time between failures (MTBF)
  3. Business impact analysis (BIA)
  4. Annualized rate of occurrence (ARO)

Correct Answer: B

 

Correct Answer

Answer B is correct because Mean time between failures (MTBF) means the average operating time between failures for a repairable component or system.

Incorrect Answers

Answer A is incorrect because Risk tolerance addresses a different requirement. Risk tolerance refers to the acceptable amount of variation or exposure around objectives.

Answer C is incorrect because Business impact analysis (BIA) addresses a different security requirement. Business impact analysis (BIA) refers to analysis of critical processes, dependencies, and consequences of disruption.

Answer D is incorrect because Annualized rate of occurrence (ARO) would fit a different scenario. Annualized rate of occurrence (ARO) refers to the expected frequency of a risk event within one year.

 

Question 25

To create the set of risks that need analysis and treatment, which security approach should be selected?

  1. Risk tolerance
  2. Risk appetite
  3. Risk identification
  4. Qualitative risk analysis

Correct Answer: C

 

Correct Answer

Answer C is correct because Risk identification means the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives.

Incorrect Answers

Answer A is incorrect because Risk tolerance represents a different security function. Risk tolerance refers to the acceptable amount of variation or exposure around objectives.

Answer B is incorrect because Risk appetite would fit a different scenario. Risk appetite refers to the overall amount and type of risk an organization is willing to pursue or retain.

Answer D is incorrect because Qualitative risk analysis addresses a different security requirement. Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high.

 

Question 26

Which risk review is performed on a defined schedule?

  1. Risk owner
  2. Business impact analysis (BIA)
  3. Risk register
  4. Recurring risk assessment

Correct Answer: D

 

Correct Answer

Answer D is correct because Recurring risk assessment means a risk review performed on a defined schedule.

Incorrect Answers

Answer A is incorrect because Risk owner addresses a different requirement. Risk owner refers to the individual or role accountable for monitoring and making decisions about a specific risk.

Answer B is incorrect because Business impact analysis (BIA) addresses a different security requirement. Business impact analysis (BIA) refers to analysis of critical processes, dependencies, and consequences of disruption.

Answer C is incorrect because Risk register represents a different security function. Risk register refers to a maintained record of identified risks, ratings, owners, responses, and status.

 

Question 27

To adapt risk understanding dynamically rather than only at periodic checkpoints, which security approach should be selected?

  1. Continuous risk assessment
  2. Risk transfer
  3. Exposure factor
  4. Risk threshold

Correct Answer: A

 

Correct Answer

Answer A is correct because Continuous risk assessment means ongoing or frequently updated assessment using current data and events.

Incorrect Answers

Answer B is incorrect because Risk transfer would fit a different scenario. Risk transfer refers to a treatment strategy that shifts some financial or operational consequence to another party.

Answer C is incorrect because Exposure factor represents a different security function. Exposure factor refers to the estimated percentage of asset value lost in one event.

Answer D is incorrect because Risk threshold addresses a different security requirement. Risk threshold refers to a defined level at which a risk or indicator requires escalation or action.

 

Question 28

Which term describes risk analysis using descriptive or ordinal ratings such as low, medium, and high?

  1. Risk avoidance
  2. Qualitative risk analysis
  3. Risk tolerance
  4. Quantitative risk analysis

Correct Answer: B

 

Correct Answer

Answer B is correct because Qualitative risk analysis means risk analysis using descriptive or ordinal ratings such as low, medium, and high.

Incorrect Answers

Answer A is incorrect because Risk avoidance addresses a different security requirement. Risk avoidance refers to a treatment strategy that eliminates the activity or condition creating the risk.

Answer C is incorrect because Risk tolerance addresses a different requirement. Risk tolerance refers to the acceptable amount of variation or exposure around objectives.

Answer D is incorrect because Quantitative risk analysis represents a different security function. Quantitative risk analysis refers to risk analysis using numerical probabilities and financial or measurable impact values.

 

Question 29

To estimate expected losses and support cost-benefit decisions, which security approach should be selected?

  1. Risk owner
  2. Single loss expectancy (SLE)
  3. Recurring risk assessment
  4. Quantitative risk analysis

Correct Answer: D

 

Correct Answer

Answer D is correct because Quantitative risk analysis means risk analysis using numerical probabilities and financial or measurable impact values.

Incorrect Answers

Answer A is incorrect because Risk owner addresses a different security requirement. Risk owner refers to the individual or role accountable for monitoring and making decisions about a specific risk.

Answer B is incorrect because Single loss expectancy (SLE) represents a different security function. Single loss expectancy (SLE) refers to the expected financial loss from one occurrence of a risk event.

Answer C is incorrect because Recurring risk assessment would fit a different scenario. Recurring risk assessment refers to a risk review performed on a defined schedule.

 

Question 30

What is the expected financial loss from one occurrence of a risk event?

  1. Risk mitigation
  2. Annualized loss expectancy (ALE)
  3. Risk identification
  4. Single loss expectancy (SLE)

Correct Answer: D

 

Correct Answer

Answer D is correct because Single loss expectancy (SLE) means the expected financial loss from one occurrence of a risk event.

Incorrect Answers

Answer A is incorrect because Risk mitigation addresses a different requirement. Risk mitigation refers to a treatment strategy that reduces likelihood or impact through controls.

Answer B is incorrect because Annualized loss expectancy (ALE) addresses a different security requirement. Annualized loss expectancy (ALE) refers to the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.

Answer C is incorrect because Risk identification represents a different security function. Risk identification refers to the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives.

 

Question 31

To convert event likelihood into an annual frequency estimate, which security approach should be selected?

  1. Risk transfer
  2. Annualized rate of occurrence (ARO)
  3. Risk register
  4. Quantitative risk analysis

Correct Answer: B

 

Correct Answer

Answer B is correct because Annualized rate of occurrence (ARO) means the expected frequency of a risk event within one year.

Incorrect Answers

Answer A is incorrect because Risk transfer addresses a different security requirement. Risk transfer refers to a treatment strategy that shifts some financial or operational consequence to another party.

Answer C is incorrect because Risk register represents a different security function. Risk register refers to a maintained record of identified risks, ratings, owners, responses, and status.

Answer D is incorrect because Quantitative risk analysis would fit a different scenario. Quantitative risk analysis refers to risk analysis using numerical probabilities and financial or measurable impact values.

 

Question 32

What is the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO?

  1. Risk identification
  2. Annualized loss expectancy (ALE)
  3. Qualitative risk analysis
  4. Key risk indicator (KRI)

Correct Answer: B

 

Correct Answer

Answer B is correct because Annualized loss expectancy (ALE) means the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.

Incorrect Answers

Answer A is incorrect because Risk identification represents a different security function. Risk identification refers to the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives.

Answer C is incorrect because Qualitative risk analysis addresses a different security requirement. Qualitative risk analysis refers to risk analysis using descriptive or ordinal ratings such as low, medium, and high.

Answer D is incorrect because Key risk indicator (KRI) addresses a different requirement. Key risk indicator (KRI) refers to a metric used to signal changes in risk exposure or conditions.

 

Question 33

To calculate the loss portion used in quantitative risk analysis, which security approach should be selected?

  1. Risk threshold
  2. Annualized loss expectancy (ALE)
  3. Exposure factor
  4. Business impact analysis (BIA)

Correct Answer: C

 

Correct Answer

Answer C is correct because Exposure factor means the estimated percentage of asset value lost in one event.

Incorrect Answers

Answer A is incorrect because Risk threshold addresses a different security requirement. Risk threshold refers to a defined level at which a risk or indicator requires escalation or action.

Answer B is incorrect because Annualized loss expectancy (ALE) would fit a different scenario. Annualized loss expectancy (ALE) refers to the expected yearly loss from a risk, commonly calculated as SLE multiplied by ARO.

Answer D is incorrect because Business impact analysis (BIA) represents a different security function. Business impact analysis (BIA) refers to analysis of critical processes, dependencies, and consequences of disruption.

 

Question 34

What is a maintained record of identified risks, ratings, owners, responses, and status?

  1. Risk identification
  2. Key risk indicator (KRI)
  3. Risk register
  4. Continuous risk assessment

Correct Answer: C

 

Correct Answer

Answer C is correct because Risk register means a maintained record of identified risks, ratings, owners, responses, and status.

Incorrect Answers

Answer A is incorrect because Risk identification represents a different security function. Risk identification refers to the process of recognizing threats, vulnerabilities, assets, scenarios, and consequences that could affect objectives.

Answer B is incorrect because Key risk indicator (KRI) addresses a different requirement. Key risk indicator (KRI) refers to a metric used to signal changes in risk exposure or conditions.

Answer D is incorrect because Continuous risk assessment addresses a different security requirement. Continuous risk assessment refers to ongoing or frequently updated assessment using current data and events.

 

Question 35

To provide early warning that risk may be increasing or controls may be weakening, which security approach should be selected?

  1. Mean time to repair (MTTR)
  2. Risk acceptance
  3. Key risk indicator (KRI)
  4. Risk appetite

Correct Answer: C

 

Correct Answer

Answer C is correct because Key risk indicator (KRI) means a metric used to signal changes in risk exposure or conditions.

Incorrect Answers

Answer A is incorrect because Mean time to repair (MTTR) would fit a different scenario. Mean time to repair (MTTR) refers to the average time needed to restore a failed component or service.

Answer B is incorrect because Risk acceptance represents a different security function. Risk acceptance refers to a treatment decision to knowingly retain a risk within approved tolerance.

Answer D is incorrect because Risk appetite addresses a different security requirement. Risk appetite refers to the overall amount and type of risk an organization is willing to pursue or retain.

img