CompTIA Security+ (SY0-701) — Question 104
Which of the following would be most useful in determining whether the long-term cost to transfer a risk is less than the impact of the risk?
Answer options
- A. ARO
- B. RTO
- C. RPO
- D. ALE
- E. SLE
Correct answer: D
Explanation
The correct answer is ALE (Annual Loss Expectancy), as it quantifies the expected yearly loss due to a specific risk, allowing comparison with the costs of risk transfer. ARO (Annual Rate of Occurrence), RTO (Recovery Time Objective), RPO (Recovery Point Objective), and SLE (Single Loss Expectancy) are useful metrics, but they do not directly assess the long-term financial implications of risk transfer versus potential impact.