nerdexam
CompTIA

SY0-701 · Question #653

A company is considering an expansion of access controls for an application that contractors and internal employees use to reduce costs. Which of the following risk elements should the…

The correct answer is B. Appetite. Risk appetite defines how much risk an organization is willing to accept in pursuit of its goals - in this case, cost reduction through expanded contractor access. Before granting access, the implementation team must understand this tolerance to ensure the decision aligns with…

Submitted by satoshi_tk· Mar 6, 2026Security program management and oversight

Question

A company is considering an expansion of access controls for an application that contractors and internal employees use to reduce costs. Which of the following risk elements should the implementation team understand before granting access to the application?

Options

  • AThreshold
  • BAppetite
  • CAvoidance
  • DRegister

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    89% (16)
  • C
    6% (1)

Explanation

Risk appetite defines how much risk an organization is willing to accept in pursuit of its goals - in this case, cost reduction through expanded contractor access. Before granting access, the implementation team must understand this tolerance to ensure the decision aligns with organizational policy and doesn't expose the company to unacceptable risk.

  • A (Threshold) is wrong because a threshold is a trigger point at which risk becomes unacceptable and requires action - it's a monitoring/escalation concept, not a foundational element to understand before an access decision.
  • C (Avoidance) is wrong because avoidance is a risk response strategy (choosing not to engage in the risky activity), not a risk element to understand beforehand.
  • D (Register) is wrong because a risk register is a documentation artifact used to track identified risks - it's a tool, not a conceptual element the team needs to understand before granting access.

Memory tip: Think of appetite as "how hungry is the organization for risk?" - just as you check your hunger before ordering food, you check risk appetite before making access decisions. The other options happen after (threshold, register) or instead of (avoidance) taking the action.

Topics

#Risk Management#Risk Appetite#Access Control

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice