Exam objective
SY0-701 5.2: Risk Management
Risk Management for Security+
This Security+ topic covers risk identification and risk assessment cadence: ad hoc, recurring, one-time, and continuous; Risk analysis concepts: qualitative, quantitative, SLE, ALE, ARO, probability, likelihood, exposure factor, and impact; Risk tracking and decision context: risk register, key risk indicators, risk owners, risk threshold, risk tolerance, risk appetite, expansionary, conservative, neutral, risk reporting, and business impact analysis; Business impact analysis values: recovery time objective (RTO), recovery point objective (RPO), mean time to repair (MTTR), and mean time between failures (MTBF).
Start first lesson4 lessons in this topic
Common mistakes to avoid
Learners often confuse ad hoc with one-time. The correction: ad hoc is event-triggered and unscheduled; one-time is planned for a specific decision or project even if it happens only once.
The most common formula confusion is reversing SLE and ALE. The correction: SLE is one event; ALE is one year. ALE equals SLE times ARO.
Learners often confuse RTO and RPO. The correction: RTO is time to restore service; RPO is amount of data loss measured in time.
Learners often think transfer means the organization no longer has risk. The correction: transfer shifts some impact or responsibility, but residual risk and accountability remain.