Domain 5.0 — Security Program Management and Oversight¶
← Back to Security+ overview · Domain weight: 20%
In progress
This domain is partial. The source paste was cut off mid-answer at Q123. Q124 onward (risk register, compliance frameworks, governance, third-party risk, security awareness training, etc.) will be added once received.
Q121. Risk formula¶
A vulnerability has a high likelihood of exploitation and would cause major business impact. What is the resulting risk level likely to be?
- A. High
- B. Zero
- C. Purely theoretical
- D. Unrelated to likelihood
Answer: A — High
Why: Risk is commonly evaluated as a function of likelihood and impact.
Q122. Risk acceptance¶
A business owner documents that fixing a low-risk issue costs more than the expected loss and formally decides not to remediate now. What is this?
- A. Risk acceptance
- B. Risk avoidance
- C. Risk transfer
- D. Risk exploitation
Answer: A — Risk acceptance
Why: Acceptance means knowingly retaining the risk with appropriate approval.
Q123. Risk transfer¶
A company buys cyber insurance to reduce financial exposure after an incident. What risk strategy is this?
- A. Transfer
- B. Avoid
- C. Ignore
- D. Eliminate completely
Answer: A — Transfer
Why: Insurance shifts some financial impact but does not remove all operational or reputational risk. (Source paste was cut off here — rest of the "Why" and Q124 onward pending.)
← Domain 4 · Back to Security+ overview