Skip to content

Domain 5.0 — Security Program Management and Oversight

← Back to Security+ overview · Domain weight: 20%

In progress

This domain is partial. The source paste was cut off mid-answer at Q123. Q124 onward (risk register, compliance frameworks, governance, third-party risk, security awareness training, etc.) will be added once received.

Q121. Risk formula

A vulnerability has a high likelihood of exploitation and would cause major business impact. What is the resulting risk level likely to be?

  • A. High
  • B. Zero
  • C. Purely theoretical
  • D. Unrelated to likelihood

Answer: A — High

Why: Risk is commonly evaluated as a function of likelihood and impact.


Q122. Risk acceptance

A business owner documents that fixing a low-risk issue costs more than the expected loss and formally decides not to remediate now. What is this?

  • A. Risk acceptance
  • B. Risk avoidance
  • C. Risk transfer
  • D. Risk exploitation

Answer: A — Risk acceptance

Why: Acceptance means knowingly retaining the risk with appropriate approval.


Q123. Risk transfer

A company buys cyber insurance to reduce financial exposure after an incident. What risk strategy is this?

  • A. Transfer
  • B. Avoid
  • C. Ignore
  • D. Eliminate completely

Answer: A — Transfer

Why: Insurance shifts some financial impact but does not remove all operational or reputational risk. (Source paste was cut off here — rest of the "Why" and Q124 onward pending.)


← Domain 4 · Back to Security+ overview