SY0-701 exam dumps

SY0-701 practice question 428 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 428

Single answerRisk register: Key risk indicators , Risk owners , Risk threshold

A healthcare company maintains a risk register for its patient billing platform. One entry lists the risk of ransomware spreading through unpatched servers. The register shows a risk threshold of 5% for critical servers missing security patches for more than 30 days. During the monthly review, the security analyst reports that 11% of critical servers are now over 30 days out of date. The infrastructure manager is listed as the risk owner. What should the organization do FIRST based on risk register best practices?

  1. A

    Accept the risk because patching windows can disrupt healthcare operations, and review the issue again next quarter

  2. B

    Escalate the risk to the risk owner because the key risk indicator exceeded the defined risk threshold

  3. C

    Remove the entry from the risk register because the issue is already being monitored by the vulnerability scanner

  4. D

    Transfer the risk to the cyber insurance provider because ransomware is a covered event

Show answer and explanation

Correct answer: B

Explanation

This question tests the relationship between three core risk register elements: key risk indicators, risk owners, and risk thresholds. The percentage of critical servers that are unpatched for more than 30 days is the KRI because it is a measurable signal of increasing ransomware exposure. The documented 5% value is the risk threshold, meaning the organization has defined that anything above that level requires attention. Because the observed value is 11%, the threshold has been exceeded. At that point, the proper first action is to involve the listed risk owner, who is accountable for reviewing the risk and selecting or escalating treatment. This follows common risk management practices described in frameworks such as NIST guidance on risk management and industry governance practices, where risks are documented with assigned ownership, monitored with measurable indicators, and acted on when tolerance or threshold limits are breached.

  • A. Incorrect.

    This is incorrect because the measured condition has exceeded the documented risk threshold. A risk threshold defines the level at which management action is required. Simply accepting the risk without formal review by the designated owner would bypass governance and risk treatment processes. Candidates may choose this if they confuse operational inconvenience with formal risk acceptance.

  • B. Correct.

    This is correct because 11% exceeds the 5% threshold, and the metric being tracked is functioning as a key risk indicator (KRI). When a KRI crosses the threshold, the designated risk owner is responsible for evaluating the situation and deciding on treatment, such as remediation, escalation, acceptance, or other response actions. This aligns with standard risk register practices in which thresholds trigger management attention and owners are accountable for the response.

  • C. Incorrect.

    This is incorrect because monitoring tools do not replace governance documentation. A vulnerability scanner may provide data for a KRI, but the risk register is where ownership, status, thresholds, and response decisions are tracked. Removing the item would reduce visibility and weaken accountability.

  • D. Incorrect.

    This is incorrect because cyber insurance does not eliminate the underlying operational risk and is not the first action when a threshold breach is detected. Risk transfer can be one treatment option in some cases, but the risk owner must first assess the exceeded threshold and determine the appropriate response. Insurance also typically includes conditions and exclusions, so it is not a substitute for patch management.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam