5.2 Explain elements of the risk management process
Objective 5.2 sits in Security Program Management and Oversight, which carries 20% of the Security+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.
Objective title verbatim from the official objectives. CompTIA exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
Which term names the overall process of identifying, assessing, and responding to threats or events that could affect an organization's objectives?
The concept
Risk management is the overarching process of identifying, assessing, and responding to threats or events that affect organizational objectives.
Why this answer
The described activity, spanning identification through response across the enterprise, matches risk management itself rather than any single artifact or subset of it.
- Correct: this is the overarching process being described.
- BA register logs individual risks; it is a tool used within the process, not the process itself.
- CAppetite is a predefined acceptable loss level, not the process of identifying and responding to threats.
- DThreat modeling is a structured technique focused on system design, narrower than enterprise risk management.
- ETolerance is a threshold for variation, not the overall identify-assess-respond process.
Now you: objective 5.2 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An online service's engineering team reviews whether existing security controls are properly designed and operating as intended, using methods shared across the company. This best illustrates which risk management element?
Sample question 2 of 3
A governance team updates its control framework after reviewing penetration test results, security incident data, and new regulatory requirements. Which risk management element primarily drove this update?
Sample question 3 of 3
Before ranking any threats, a team builds diagrams showing trust boundaries, data flows, and external entities interacting with a new application. This modeling step primarily supports which later risk management activity?
That’s 3 of the full Security+ bank.
Keep going free: 10 questions per certification in bank practice, with no account.
Continue practicingRead the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.
More objectives in Security Program Management and Oversight
- 5.1 5.1 Summarize elements of effective security governance
- 5.3 5.3 Explain the processes associated with third-party risk assessment and management
- 5.4 5.4 Summarize elements of effective security compliance
- 5.5 5.5 Explain types and purposes of audits and assessments
- 5.6 5.6 Given a scenario, implement security awareness practices