SY0-701 Question 432
Single answerRisk appetite: Expansionary , Conservative , NeutralA retail company is expanding into online sales and plans to launch a new mobile checkout feature before the holiday season. During a risk review, the CISO notes that the feature relies on a recently integrated third-party payment SDK that has not yet completed the organization's full internal security testing cycle. The CEO states that missing the launch window would significantly reduce projected revenue, but the board still requires compliance with PCI DSS and wants risks documented and managed. Which risk appetite BEST describes the board's position?
- A
Expansionary, because the organization is willing to accept higher risk to pursue growth and revenue opportunities while still applying required controls
- B
Conservative, because the organization should delay the launch until every internal security test is complete regardless of business impact
- C
Neutral, because the organization is ignoring both the revenue opportunity and the security concerns until after the launch
- D
Risk avoidance, because the organization is eliminating the use of third-party software to remove uncertainty
Show answer and explanation
Correct answer: A
Explanation
Risk appetite describes how much risk an organization is willing to accept in pursuit of objectives. In Security+ terms, an expansionary appetite aligns with organizations that tolerate more risk to enable growth, innovation, or speed to market, as long as legal, regulatory, and business constraints are still addressed. A conservative appetite would favor minimizing exposure and delaying action until more certainty exists. A neutral appetite is more balanced and does not imply ignoring risk. This scenario is expansionary because leadership is prioritizing a revenue-driving launch despite incomplete internal testing, while still requiring compliance and formal risk management. This is consistent with common governance practices in frameworks such as NIST Risk Management Framework concepts for risk decisions and PCI DSS requirements for protecting payment environments while documenting and managing residual risk.
- A. Correct.
Correct. An expansionary risk appetite means the organization is more willing to accept risk in order to achieve business growth, market share, or revenue goals. In this scenario, leadership wants to proceed to meet a critical sales deadline, but not recklessly, they still require PCI DSS compliance and documented risk management. That reflects a higher tolerance for risk in support of strategic expansion, not a disregard for security.
- B. Incorrect.
Incorrect. A conservative risk appetite reflects low tolerance for risk and would favor delaying or limiting the rollout until uncertainty is reduced as much as possible. While some organizations would choose this path, the scenario specifically emphasizes the business priority of launching on time and accepting managed risk rather than postponing the release.
- C. Incorrect.
Incorrect. A neutral risk appetite generally reflects a balanced approach, weighing business value and risk without strongly favoring aggressive growth or highly restrictive controls. This option is wrong because it describes inaction and neglect rather than balanced decision-making. The organization is actively making a decision, documenting risk, and maintaining compliance obligations.
- D. Incorrect.
Incorrect. Risk avoidance is a risk response strategy, not a risk appetite category in this context. It would involve changing plans to avoid the risk entirely, such as not using the SDK or canceling the feature. The scenario describes acceptance of some managed risk for business benefit, which aligns with an expansionary appetite rather than avoidance.