SY0-701 exam dumps

SY0-701 practice question 431 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 431

Single answerRisk appetite: Expansionary , Conservative , Neutral

A company is launching a new customer analytics platform in a highly competitive market. During a governance meeting, the CISO explains that leadership is willing to accept higher short-term cybersecurity risk to gain market share quickly, as long as legal and regulatory requirements are still met. Which risk appetite best describes the organization's position?

  1. A

    Expansionary risk appetite, because the organization is willing to accept more risk in pursuit of business growth

  2. B

    Conservative risk appetite, because the organization is prioritizing strict risk avoidance over speed to market

  3. C

    Neutral risk appetite, because the organization is balancing all risks equally and avoiding any meaningful tradeoff

  4. D

    Risk transference, because the organization can eliminate most of the business risk by purchasing cyber insurance

Show answer and explanation

Correct answer: A

Explanation

Risk appetite describes the amount and type of risk an organization is willing to accept in pursuit of its objectives. In Security+ governance and risk discussions, an expansionary appetite is associated with organizations that are more comfortable taking risks to support growth, innovation, or speed to market. A conservative appetite indicates low tolerance for uncertainty and stronger preference for risk avoidance and control. A neutral appetite falls between those extremes and typically evaluates risk in a more balanced, case-by-case manner. This scenario clearly indicates an expansionary posture because leadership is intentionally accepting more cybersecurity risk to gain market share. This aligns with common risk management guidance in frameworks such as NIST SP 800-39, which discusses risk tolerance and organizational risk framing, and with enterprise governance practices that distinguish business objectives from risk treatment methods like mitigation, acceptance, avoidance, and transference.

  • A. Correct.

    Correct. An expansionary risk appetite means leadership is more willing to accept risk when pursuing opportunities such as rapid growth, innovation, or competitive advantage. In this scenario, the company is knowingly accepting higher short-term cybersecurity risk to accelerate market entry, which aligns with an expansionary posture. The key detail is that the organization is not ignoring compliance requirements, but it is tolerating more operational risk to achieve a business objective.

  • B. Incorrect.

    Incorrect. A conservative risk appetite reflects low tolerance for risk and typically emphasizes stability, strong controls, and minimizing exposure even if it slows business initiatives. That does not match this scenario, where leadership is explicitly accepting more risk to move faster.

  • C. Incorrect.

    Incorrect. A neutral risk appetite generally reflects a moderate or balanced willingness to accept risk based on cost-benefit analysis, rather than a clear preference toward aggressive growth or strict avoidance. In this case, leadership is signaling a stronger-than-moderate willingness to accept risk for strategic gain, which is more accurately described as expansionary.

  • D. Incorrect.

    Incorrect. Risk transference is a risk treatment method, not a risk appetite category. Purchasing cyber insurance may transfer some financial impact, but it does not describe leadership's overall willingness to take on risk. The question asks about organizational appetite, not a specific control or treatment strategy.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam