Objective 5.2SY0-701

5.2 Explain elements of the risk management process

Objective 5.2 sits in Security Program Management and Oversight, which carries 20% of the Security+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Security Program Management and OversightEasy

Which term names the overall process of identifying, assessing, and responding to threats or events that could affect an organization's objectives?

Correct.

The concept

Risk management is the overarching process of identifying, assessing, and responding to threats or events that affect organizational objectives.

Why this answer

The described activity, spanning identification through response across the enterprise, matches risk management itself rather than any single artifact or subset of it.

  • Correct: this is the overarching process being described.
  • BA register logs individual risks; it is a tool used within the process, not the process itself.
  • CAppetite is a predefined acceptable loss level, not the process of identifying and responding to threats.
  • DThreat modeling is a structured technique focused on system design, narrower than enterprise risk management.
  • ETolerance is a threshold for variation, not the overall identify-assess-respond process.
Read the sourceMicrosoft Learn: Governance, risk, and compliance
Verified against cheatsheetseries.owasp.org · 2026-07-27
risk managementdefinitiongovernance

Now you: objective 5.2 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Security Program Management and OversightModerate

An online service's engineering team reviews whether existing security controls are properly designed and operating as intended, using methods shared across the company. This best illustrates which risk management element?

Sample question 2 of 3

Security Program Management and OversightHard

A governance team updates its control framework after reviewing penetration test results, security incident data, and new regulatory requirements. Which risk management element primarily drove this update?

Sample question 3 of 3

Security Program Management and OversightModerate

Before ranking any threats, a team builds diagrams showing trust boundaries, data flows, and external entities interacting with a new application. This modeling step primarily supports which later risk management activity?

That’s 3 of the full Security+ bank.

Keep going free: 10 questions per certification in bank practice, with no account.

Continue practicing

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security Program Management and Oversight