nerdexam
CompTIA

SY0-701 · Question #305

In a rush to meet an end-of-year business goal, the IT department was told to implement a new business application. The security engineer reviews the attributes of the application and decides the…

The correct answer is D. Risk appetite. Risk appetite refers to the level of risk that an organization is willing to accept in order to achieve its objectives. In this scenario, the security engineer is concerned that the timeframe for implementing a new application does not allow for sufficient cybersecurity due…

Submitted by ashley.k· Mar 6, 2026Security program management and oversight

Question

In a rush to meet an end-of-year business goal, the IT department was told to implement a new business application. The security engineer reviews the attributes of the application and decides the time needed to perform due diligence is insufficient from a cybersecurity perspective. Which of the following best describes the security engineer's response?

Options

  • ARisk tolerance
  • BRisk acceptance
  • CRisk importance
  • DRisk appetite

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    5% (2)
  • D
    93% (38)

Explanation

Risk appetite refers to the level of risk that an organization is willing to accept in order to achieve its objectives. In this scenario, the security engineer is concerned that the timeframe for implementing a new application does not allow for sufficient cybersecurity due diligence. This reflects a situation where the organization's risk appetite might be too high if it proceeds without the necessary security checks.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice