In the process of developing a data protection strategy, a cybersecurity analyst must understand the extent of potential data breaches that the organization is prepared to handle. What term describes this concept?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: A
- ACorrect: Risk tolerance is the amount of loss or variation, such as breach impact, that the organization is prepared to handle; CS0-004 uses the broader term risk appetite for the overall willingness to take on risk, and since appetite is not offered, tolerance is the best fit.
- BRisk perception is how people subjectively judge a risk, not a limit the organization sets for itself.
- CRisk absorption is not a standard risk-management term; absorbing a loss is closer to accepting a risk than to defining how much the organization can handle.
- DRisk avoidance is a risk response that stops the risky activity altogether and does not measure how much breach impact the organization can absorb.