U.S. Independence Day Deal! Unlock 25% OFF Today – Limited-Time Offer - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IIBA-CCA Exam - Topic 1 Question 8 Discussion

Organizations who don't quantify this will likely miss opportunities toward achieving strategic goals and objectives:
D) risk appetite.
A) cybersecurity budget.
B) control effectiveness.
C) risk estimation.

IIBA-CCA Exam - Topic 1 Question 8 Discussion

Actual exam question for IIBA's IIBA-CCA exam
Question #: 8
Topic #: 1
[All IIBA-CCA Questions]

Organizations who don't quantify this will likely miss opportunities toward achieving strategic goals and objectives:

Show Suggested Answer Hide Answer
Suggested Answer: D

Risk appetite is the amount and type of risk an organization is willing to pursue or retain in order to achieve its objectives. Cybersecurity and enterprise risk management guidance treats risk appetite as a strategic input because it shapes decision-making across portfolios, programs, and day-to-day operations. When risk appetite is quantified through measurable statements and thresholds, leaders can compare proposed initiatives against agreed limits and make consistent trade-offs between speed, cost, innovation, and protection.

If an organization does not quantify risk appetite, it often defaults to inconsistent behavior: some teams become overly cautious and reject beneficial initiatives, while others take uncontrolled risk because there is no clear boundary. Both outcomes can cause missed opportunities. Over-caution can delay digital transformation, cloud adoption, automation, and new customer capabilities. Under-defined boundaries can also lead to surprise losses, regulatory issues, and unplanned remediation that consumes budget and time---reducing the organization's ability to execute strategy.

Quantified risk appetite enables practical governance: it guides which risks can be accepted, which require mitigation, and which must be escalated for executive decision. It also supports prioritization of security investments by focusing resources on risks that exceed tolerance and allowing faster approval for activities that fall within appetite. In short, risk appetite is the strategic ''north star'' that aligns cybersecurity risk-taking with business goals, making option D the correct choice.


Contribute your Thoughts:

0/2000 characters
Jean
1 month ago
I think B) control effectiveness is more important.
upvoted 0 times
...
Jose
2 months ago
Definitely A) cybersecurity budget! It's crucial.
upvoted 0 times
...
Iraida
2 months ago
I’m leaning towards B) control effectiveness, but I’m not confident. It’s tricky to remember all the details!
upvoted 0 times
...
Ashton
2 months ago
I feel like this question is similar to one we practiced on budgeting for cybersecurity. Could it be A)?
upvoted 0 times
...
Edison
2 months ago
I'm not entirely sure, but I remember something about D) risk appetite being important for aligning goals.
upvoted 0 times
...
Vi
3 months ago
I think it might be C) risk estimation, since quantifying risks seems crucial for strategic planning.
upvoted 0 times
...

Save Cancel