nerdexam
EC-Council

712-50 · Question #336

Risk appetite directly affects what part of a vulnerability management program?

The correct answer is B. Scope. Scope (B) is correct because risk appetite - the amount of risk an organization is willing to accept - directly determines which assets, systems, and networks are included in vulnerability scanning. An organization with low risk tolerance will cast a wide net (broad scope)…

Security Program Management & Operations

Question

Risk appetite directly affects what part of a vulnerability management program?

Options

  • AStaff
  • BScope
  • CSchedule
  • DScan tools

How the community answered

(28 responses)
  • A
    18% (5)
  • B
    71% (20)
  • C
    7% (2)
  • D
    4% (1)

Explanation

Scope (B) is correct because risk appetite - the amount of risk an organization is willing to accept - directly determines which assets, systems, and networks are included in vulnerability scanning. An organization with low risk tolerance will cast a wide net (broad scope), while one accepting higher risk may exclude certain low-priority systems, limiting the program's reach.

Staff (A) is unaffected by risk appetite directly; headcount and roles are driven by budget and operational needs, not risk tolerance thresholds.

Schedule (C) is driven by compliance requirements, operational windows, and asset criticality cadence - not by how much risk the organization is willing to accept.

Scan tools (D) are selected based on technical requirements, asset types, and budget - risk appetite doesn't dictate which scanner you buy.

Memory tip: Think of risk appetite as drawing a fence around what you protect. The bigger the fence (low risk tolerance), the wider the scope of what gets scanned. "Appetite = Area covered."

Topics

#Risk Appetite#Vulnerability Management#Program Scope#Risk Management

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice