Exam objective

SY0-701 5.2: Risk Management

Security+ Topic

Risk Management for Security+

This Security+ topic covers risk identification and risk assessment cadence: ad hoc, recurring, one-time, and continuous; Risk analysis concepts: qualitative, quantitative, SLE, ALE, ARO, probability, likelihood, exposure factor, and impact; Risk tracking and decision context: risk register, key risk indicators, risk owners, risk threshold, risk tolerance, risk appetite, expansionary, conservative, neutral, risk reporting, and business impact analysis; Business impact analysis values: recovery time objective (RTO), recovery point objective (RPO), mean time to repair (MTTR), and mean time between failures (MTBF).

Start first lesson

4 lessons in this topic

Common mistakes to avoid

1

Learners often confuse ad hoc with one-time. The correction: ad hoc is event-triggered and unscheduled; one-time is planned for a specific decision or project even if it happens only once.

2

The most common formula confusion is reversing SLE and ALE. The correction: SLE is one event; ALE is one year. ALE equals SLE times ARO.

3

Learners often confuse RTO and RPO. The correction: RTO is time to restore service; RPO is amount of data loss measured in time.

4

Learners often think transfer means the organization no longer has risk. The correction: transfer shifts some impact or responsibility, but residual risk and accountability remain.