Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IIBA-CCA Exam - Topic 1 Question 8 Discussion

Organizations who don't quantify this will likely miss opportunities toward achieving strategic goals and objectives:
D) risk appetite.
A) cybersecurity budget.
B) control effectiveness.
C) risk estimation.

IIBA-CCA Exam - Topic 1 Question 8 Discussion

Actual exam question for IIBA's IIBA-CCA exam
Question #: 8
Topic #: 1
[All IIBA-CCA Questions]

Organizations who don't quantify this will likely miss opportunities toward achieving strategic goals and objectives:

Show Suggested Answer Hide Answer
Suggested Answer: D

Risk appetite is the amount and type of risk an organization is willing to pursue or retain in order to achieve its objectives. Cybersecurity and enterprise risk management guidance treats risk appetite as a strategic input because it shapes decision-making across portfolios, programs, and day-to-day operations. When risk appetite is quantified through measurable statements and thresholds, leaders can compare proposed initiatives against agreed limits and make consistent trade-offs between speed, cost, innovation, and protection.

If an organization does not quantify risk appetite, it often defaults to inconsistent behavior: some teams become overly cautious and reject beneficial initiatives, while others take uncontrolled risk because there is no clear boundary. Both outcomes can cause missed opportunities. Over-caution can delay digital transformation, cloud adoption, automation, and new customer capabilities. Under-defined boundaries can also lead to surprise losses, regulatory issues, and unplanned remediation that consumes budget and time---reducing the organization's ability to execute strategy.

Quantified risk appetite enables practical governance: it guides which risks can be accepted, which require mitigation, and which must be escalated for executive decision. It also supports prioritization of security investments by focusing resources on risks that exceed tolerance and allowing faster approval for activities that fall within appetite. In short, risk appetite is the strategic ''north star'' that aligns cybersecurity risk-taking with business goals, making option D the correct choice.


Contribute your Thoughts:

0/2000 characters
Lauran
2 days ago
I'm leaning towards A) cybersecurity budget. It's essential for protection.
upvoted 0 times
...
Horace
7 days ago
I agree, Alice. Risk appetite is also crucial, D) could be the answer.
upvoted 0 times
...
Kallie
12 days ago
I think it's C) risk estimation. Without it, you can't plan properly.
upvoted 0 times
...
Dion
18 days ago
C) risk estimation is vital. It helps prioritize actions and resources.
upvoted 0 times
...
Winfred
23 days ago
A) cybersecurity budget makes sense. Without funds, how can you protect assets?
upvoted 0 times
...
Valentin
28 days ago
I feel like B) control effectiveness is key. Without it, you can't measure success.
upvoted 0 times
...
Kanisha
1 month ago
D) risk appetite seems important too. Organizations need to know their limits.
upvoted 0 times
...
Alecia
1 month ago
I lean towards C) risk estimation. It's crucial for planning.
upvoted 0 times
...
Edelmira
1 month ago
I think it's definitely A) cybersecurity budget.
upvoted 0 times
...
Lewis
2 months ago
Totally agree with A) - can't ignore the budget!
upvoted 0 times
...
Veronika
2 months ago
Wait, D) risk appetite? Isn't that a bit vague?
upvoted 0 times
...
Oliva
2 months ago
C) risk estimation is key for any strategy.
upvoted 0 times
...
Ressie
2 months ago
I think B) control effectiveness is more important.
upvoted 0 times
...
Celeste
2 months ago
Definitely A) cybersecurity budget! It's crucial.
upvoted 0 times
...
Benedict
2 months ago
Not sure about this... can we really measure all of this effectively?
upvoted 0 times
...
Linette
3 months ago
Totally agree with A), but C) risk estimation is also key!
upvoted 0 times
...
Frank
3 months ago
Wait, are we really missing out on opportunities if we don’t quantify D) risk appetite?
upvoted 0 times
...
Jean
4 months ago
I think B) control effectiveness is more important.
upvoted 0 times
...
Jose
5 months ago
Definitely A) cybersecurity budget! It's crucial.
upvoted 0 times
...
Iraida
5 months ago
I’m leaning towards B) control effectiveness, but I’m not confident. It’s tricky to remember all the details!
upvoted 0 times
...
Ashton
5 months ago
I feel like this question is similar to one we practiced on budgeting for cybersecurity. Could it be A)?
upvoted 0 times
...
Edison
5 months ago
I'm not entirely sure, but I remember something about D) risk appetite being important for aligning goals.
upvoted 0 times
...
Vi
6 months ago
I think it might be C) risk estimation, since quantifying risks seems crucial for strategic planning.
upvoted 0 times
...

Save Cancel