Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 712-50 Exam - Topic 4 Question 125 Discussion

The company decides to release the application without remediating the high-risk vulnerabilities. Which of the following is the MOST likely reason for the company to release the application?
C) The company has a high risk tolerance
A) The company lacks a risk management process
B) The company does not believe the security vulnerabilities to be real
D) The company lacks the tools to perform a vulnerability assessment

Eccouncil 712-50 Exam - Topic 4 Question 125 Discussion

Actual exam question for Eccouncil's 712-50 exam
Question #: 125
Topic #: 4
[All 712-50 Questions]

The company decides to release the application without remediating the high-risk vulnerabilities. Which of the following is the MOST likely reason for the company to release the application?

Show Suggested Answer Hide Answer
Suggested Answer: C

* Risk Tolerance in Decision-Making:

Organizations with high risk tolerance may accept certain vulnerabilities due to business priorities, such as meeting market deadlines or competitive pressures.

* Key Considerations:

This decision reflects a calculated trade-off between security and business objectives.

Risk acceptance is documented in a formal risk management process to ensure accountability.

* Why Not Other Options:

Lack of risk management process (A): Would indicate an unstructured approach, which is less likely in this context.

Believing vulnerabilities are not real (B): Unlikely for high-risk vulnerabilities.

Lacking tools for assessment (D): Does not explain why the release proceeds despite known vulnerabilities.

* EC-Council CISO Framework:

Decision-making must align with the organization's risk appetite, a principle central to the EC-Council CISO program.


Contribute your Thoughts:

0/2000 characters
Nina
4 days ago
D seems unlikely. Most companies have at least basic tools for assessments.
upvoted 0 times
...
Emiko
9 days ago
Wait, how can they release it with high-risk vulnerabilities? That's wild!
upvoted 0 times
...
Tonette
14 days ago
A makes sense too. If there's no risk management, they might not even know!
upvoted 0 times
...
Weldon
19 days ago
I disagree, it's more likely C. Some companies just take risks.
upvoted 0 times
...
Virgilio
24 days ago
Definitely think it's B. They probably don't see the vulnerabilities as a threat.
upvoted 0 times
...
Alton
29 days ago
I vaguely recall something about tools for vulnerability assessments. Option D seems less likely, but it could be a factor if they really can't assess the risks properly.
upvoted 0 times
...
Avery
1 month ago
I think we had a practice question about risk management processes, and it seems like A could be a possibility too. If they lack that, they might not know how to handle the risks.
upvoted 0 times
...
Kallie
1 month ago
I'm not entirely sure, but I feel like option B could also be a reason. If they don't see the vulnerabilities as real, they might just push the app out.
upvoted 0 times
...
Marjory
1 month ago
I remember discussing risk tolerance in class, so I think option C might be the right choice. Companies sometimes prioritize speed over security.
upvoted 0 times
...

Save Cancel