A company is considering an expansion of access controls for an application that contractors and internal employees use to reduce costs. Which of the following risk elements should the implementation team understand before granting access to the application?
Choose an answer
Tap an option to check your answer.
Correct answer: Appetite.
Why this is the answer
Risk appetite refers to the amount of risk an organization is willing to accept in pursuit of its objectives. Before expanding access controls, the implementation team must understand the company's risk appetite to ensure the new controls align with the acceptable level of exposure. Granting access to more users, especially contractors, inherently introduces new risks (e.g., data breaches, unauthorized access). If the company has a low risk appetite, more stringent controls and vetting processes will be necessary. If the appetite is higher, a more flexible approach might be adopted. Threshold is the point at which a risk becomes unacceptable, but appetite defines the overall willingness to take on risk. Avoidance is a risk response strategy, not an element to understand before implementation. A risk register is a document that records risks, not a risk element itself.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed