SY0-701 exam dumps

SY0-701 practice question 427 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 427

Single answerRisk register: Key risk indicators , Risk owners , Risk threshold

A healthcare company tracks third-party vendor risks in a risk register. One entry covers a cloud billing provider that stores protected health information. The risk register lists the Chief Compliance Officer as the risk owner and defines a risk threshold stating that any vendor handling PHI must maintain a critical vulnerability remediation time of 15 days or less. A key risk indicator (KRI) for this entry is the vendor's average time to remediate critical vulnerabilities. During the quarterly review, the security analyst finds the vendor's average remediation time has increased from 12 days to 21 days for the last two months. Which action should the organization take FIRST?

  1. A

    Update the risk register to show the KRI has exceeded the risk threshold and escalate the issue to the risk owner for a response decision

  2. B

    Remove the vendor from the risk register because the issue is already documented through the KRI trend

  3. C

    Accept the risk automatically because the vendor was previously below the threshold and no breach has occurred

  4. D

    Transfer ownership of the risk to the security analyst because the analyst discovered the threshold violation

Show answer and explanation

Correct answer: A

Explanation

This question tests the relationship between key risk indicators, risk thresholds, and risk owners in a risk register. A KRI is a measurable signal used to monitor changes in risk exposure. A risk threshold defines the level at which the organization considers the risk outside acceptable tolerance. When a KRI exceeds that threshold, the risk register should be updated and the assigned risk owner should be engaged to determine treatment. This aligns with common risk management practices found in governance frameworks such as NIST SP 800-39, which emphasizes ongoing risk monitoring and organizational risk response, and NIST SP 800-137, which supports continuous monitoring concepts. The key point is that analysts provide visibility, thresholds define trigger points, and risk owners are accountable for the response decision.

  • A. Correct.

    Correct. The KRI is the measured indicator, and it now shows the vendor is outside the defined risk threshold. In a risk register process, the appropriate first step is to update the risk status and notify or escalate to the designated risk owner, who is accountable for deciding whether to accept, mitigate, transfer, or avoid the risk. This reflects proper governance and separation between monitoring and decision-making.

  • B. Incorrect.

    Incorrect. Risks should not be removed from the risk register simply because they are being tracked by a KRI. In fact, exceeding a threshold usually means the risk requires more attention, not removal. This option confuses monitoring data with closure criteria.

  • C. Incorrect.

    Incorrect. Prior performance below the threshold does not justify automatic risk acceptance once the current KRI shows the risk is outside tolerance. Also, the absence of a breach does not mean the risk is acceptable. Risk thresholds are used to trigger action before an incident occurs.

  • D. Incorrect.

    Incorrect. Discovering a risk issue does not make the analyst the risk owner. The risk owner is the person or role assigned accountability for that specific risk entry, in this case the Chief Compliance Officer. Analysts monitor and report; owners decide and are accountable.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam