712-50 · Question #336
Risk appetite directly affects what part of a vulnerability management program?
The correct answer is B. Scope. Scope (B) is correct because risk appetite - the amount of risk an organization is willing to accept - directly determines which assets, systems, and networks are included in vulnerability scanning. An organization with low risk tolerance will cast a wide net (broad scope)…
Question
Risk appetite directly affects what part of a vulnerability management program?
Options
- AStaff
- BScope
- CSchedule
- DScan tools
How the community answered
(28 responses)- A18% (5)
- B71% (20)
- C7% (2)
- D4% (1)
Explanation
Scope (B) is correct because risk appetite - the amount of risk an organization is willing to accept - directly determines which assets, systems, and networks are included in vulnerability scanning. An organization with low risk tolerance will cast a wide net (broad scope), while one accepting higher risk may exclude certain low-priority systems, limiting the program's reach.
Staff (A) is unaffected by risk appetite directly; headcount and roles are driven by budget and operational needs, not risk tolerance thresholds.
Schedule (C) is driven by compliance requirements, operational windows, and asset criticality cadence - not by how much risk the organization is willing to accept.
Scan tools (D) are selected based on technical requirements, asset types, and budget - risk appetite doesn't dictate which scanner you buy.
Memory tip: Think of risk appetite as drawing a fence around what you protect. The bigger the fence (low risk tolerance), the wider the scope of what gets scanned. "Appetite = Area covered."
Topics
Community Discussion
No community discussion yet for this question.