SY0-701 Question 420
Single answer5.2 Explain elements of the risk management process.A healthcare company is preparing to launch a new patient portal that will store protected health information (PHI) in a cloud-hosted database. During a risk workshop, the security analyst identifies that the database is internet-accessible and that a misconfiguration could expose patient records. The analyst estimates the probability of this happening as moderate and the business impact as severe due to regulatory penalties and reputational damage. Management asks what the analyst should do next as part of the risk management process to help determine whether additional security controls are justified. Which of the following is the BEST next step?
- A
Calculate the risk level by combining the likelihood and impact of the identified threat
- B
Accept the risk because cloud providers are responsible for protecting hosted databases
- C
Transfer the risk by purchasing cyber insurance before evaluating the severity
- D
Avoid the risk by canceling the patient portal project immediately
Show answer and explanation
Correct answer: A
Explanation
This question tests understanding of core elements of the risk management process: identifying assets and threats, analyzing vulnerabilities, estimating likelihood and impact, determining risk level, and then selecting a risk response. In the scenario, the analyst has already identified the exposure and estimated likelihood and impact. The best next step is to calculate or determine the overall risk level so management can make an informed treatment decision. This aligns with common risk management practices described in frameworks such as NIST SP 800-30 (Guide for Conducting Risk Assessments) and NIST SP 800-39 (Managing Information Security Risk), which emphasize assessing likelihood and impact before selecting a response such as mitigation, acceptance, transference, or avoidance. For Security+, candidates should recognize that treatment decisions should follow risk analysis, not precede it.
- A. Correct.
Correct. After identifying a threat/vulnerability scenario and estimating likelihood and impact, the next step is to determine or calculate the risk level so the organization can prioritize treatment. In common risk management approaches, risk is derived from the relationship between likelihood and impact, whether qualitatively (for example, low/medium/high) or quantitatively. This supports decisions about whether to mitigate, transfer, accept, or avoid the risk.
- B. Incorrect.
Incorrect. This reflects a misunderstanding of shared responsibility in cloud environments. While a cloud provider may secure the underlying infrastructure, the customer is typically responsible for configuration, access control, and data protection settings. Risk acceptance should also occur only after evaluating the risk and confirming it falls within the organization's risk appetite or tolerance.
- C. Incorrect.
Incorrect. Risk transfer is a possible treatment option, but it is not the best next step at this stage. The organization must first assess and rate the risk to determine whether transfer, mitigation, acceptance, or avoidance is appropriate. In addition, cyber insurance does not replace security controls or eliminate compliance obligations related to PHI exposure.
- D. Incorrect.
Incorrect. Risk avoidance means eliminating the activity that creates the risk, but immediately canceling the project would be premature. Avoidance is a business decision that may be considered after the risk has been analyzed and compared against organizational objectives, risk appetite, and alternative control options.