SY0-701 Question 419
Single answer5.2 Explain elements of the risk management process.A healthcare company is preparing to roll out a new cloud-based patient scheduling platform. During a risk workshop, the security manager identifies that the vendor stores application logs for 12 months, including some user identifiers, and that unauthorized disclosure could trigger regulatory penalties and reputational damage. The platform must be deployed within 60 days to meet a business deadline. The Chief Information Security Officer asks which action should be performed NEXT as part of a proper risk management process. Which of the following is the BEST answer?
- A
Determine the likelihood and impact of the identified exposure so the organization can assign a risk rating and decide on treatment
- B
Purchase cyber insurance immediately because potential regulatory penalties make this a high-risk deployment
- C
Accept the risk because the project has a fixed deployment deadline and delaying implementation would affect operations
- D
Skip formal analysis and implement every available security control from the vendor to eliminate the risk
Show answer and explanation
Correct answer: A
Explanation
The best answer is to determine likelihood and impact so the organization can assign a risk rating and select an appropriate treatment. In standard risk management, the sequence typically includes identifying assets, threats, vulnerabilities, and exposures; analyzing risk in terms of likelihood and impact; evaluating that risk against organizational tolerance; and then choosing a response such as mitigate, transfer, accept, or avoid. In this scenario, the security manager has already identified an exposure and some potential consequences, but a formal risk analysis is still needed before deciding on insurance, acceptance, or specific controls. This aligns with broadly accepted guidance such as NIST SP 800-30, Guide for Conducting Risk Assessments, and NIST SP 800-39, Managing Information Security Risk, which emphasize assessing likelihood and impact as part of risk determination before response selection. CompTIA Security+ expects candidates to understand this practical flow rather than jump directly to a treatment decision.
- A. Correct.
Correct. After identifying a threat/exposure and the potential business consequences, the next step in the risk management process is to analyze the risk by evaluating likelihood and impact. This enables the organization to determine the risk level and choose an appropriate response such as mitigation, transfer, acceptance, or avoidance. In this scenario, the organization has identified a possible confidentiality issue and business/regulatory consequences, but it still needs to assess probability and severity before selecting treatment.
- B. Incorrect.
Incorrect. Purchasing cyber insurance is a form of risk transfer, but selecting transfer before completing risk analysis is premature. The organization should first assess likelihood and impact, compare the risk against tolerance, and then decide whether transfer is appropriate. A common misconception is that any compliance-related concern should immediately result in insurance or outsourcing, but risk treatment decisions should follow analysis.
- C. Incorrect.
Incorrect. Risk acceptance is a valid treatment option only after the organization understands the risk and determines it falls within risk appetite or tolerance. A project deadline alone is not sufficient justification to accept a potentially significant confidentiality and regulatory risk. This option reflects the common error of letting schedule pressure replace formal risk evaluation.
- D. Incorrect.
Incorrect. Implementing every possible control without analysis is not a sound risk management practice. Security programs should apply controls based on assessed risk, cost, feasibility, and business requirements. It is also unrealistic to assume all risk can be eliminated. This distractor targets the misconception that more controls are automatically better, even when they are not prioritized through a risk-based process.