SY0-701 Question 430
Single answerRisk toleranceA healthcare company is preparing to launch a new patient scheduling portal. The security team identifies that adding phishing-resistant MFA for all patients would significantly reduce account takeover risk, but the implementation would delay the launch by three months and exceed the approved budget. Executive leadership decides to launch on time with password-based authentication and basic rate limiting, while documenting the remaining account takeover risk and planning to add stronger controls in the next release. Which risk response best describes this decision?
- A
Risk avoidance, because leadership is eliminating the risk by delaying deployment of the stronger control
- B
Risk transference, because leadership is shifting the account takeover risk to the portal users
- C
Risk acceptance, because leadership understands the residual risk and chooses to operate within its risk tolerance
- D
Risk mitigation, because leadership fully reduced the likelihood of account takeover to an acceptable level before launch
Show answer and explanation
Correct answer: C
Explanation
This scenario tests the difference between risk treatment strategies and the role of risk tolerance in business decisions. Risk tolerance is the level of risk an organization is willing to accept in pursuit of its objectives. Here, leadership balances security benefit, cost, and time-to-market, then formally documents and accepts the residual risk until a later release. That is a classic example of risk acceptance.
In Security+ contexts, candidates should distinguish among the common responses: avoid the risk by not performing the activity, mitigate the risk by applying controls to reduce likelihood or impact, transfer the risk through insurance or third-party arrangements, or accept the risk when it falls within organizational tolerance. This aligns with standard risk management practices described by NIST risk management guidance, including the concept of residual risk after controls are considered and the requirement for leadership to make risk-based decisions consistent with business needs.
- A. Incorrect.
This is incorrect. Risk avoidance means changing plans to eliminate the activity that creates the risk, such as not launching the portal or removing the exposed functionality entirely. In this scenario, the company is still launching the portal and continuing the risky activity, so it is not avoiding the risk.
- B. Incorrect.
This is incorrect. Risk transference involves shifting some financial or operational impact of a risk to another party, typically through cyber insurance, outsourcing, or contractual arrangements. Simply launching with weaker controls does not transfer the risk to users in the formal risk management sense.
- C. Correct.
This is correct. Leadership reviewed the risk, recognized that stronger controls would exceed budget and timeline constraints, documented the remaining exposure, and chose to proceed. That is risk acceptance. The key link to risk tolerance is that the organization decided the residual risk was within the amount of risk it was willing to tolerate temporarily in order to meet business objectives.
- D. Incorrect.
This is incorrect. Risk mitigation means implementing controls to reduce likelihood or impact, but the scenario does not indicate the risk was fully reduced to an acceptable level before launch. Basic rate limiting may provide some mitigation, but the decision point described is that leadership knowingly proceeds despite residual risk. That is acceptance of residual risk, not complete mitigation.