What Type of Risk Assessment Is Performed Annually?

Risk Management

A company is required to perform a risk assessment on an annual basis. Which of the following types of risk assessments does this requirement describe?

  1. Continuous
  2. Ad hoc
  3. Recurring Source Reference Answer
  4. One time

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the ability to map assessment schedules to their correct operational categories, with the primary trap being the confusion between periodic cycles and singular or constant execution.

This question evaluates understanding of risk assessment scheduling frequencies within security governance frameworks. Community consensus confirms that annual evaluations are definitively classified as recurring assessments due to their structured, periodic nature.

One time: Test-takers frequently misread annual as a standalone event rather than a repeating yearly obligation, failing to recognize the cyclical mandate embedded in the scenario.

Community Discussion (3 comments)

Catalyst33 👍 1 Selected: C
Continous: Its not because that would mean running software continously to evaluate risks Ad hoc: its not because that one is as the name implies decided to be done on the spur of the moment (or as a reaction) Reccuring: yes because its something pre planned which reoccurs One time: Per year means every year, not just one time
dbrowndiver 👍 4 Selected: C
Recurring risk assessments are those that are scheduled to take place at regular intervals, such as annually, semi-annually, or quarterly. This type of assessment ensures that risks are regularly evaluated, allowing the company to stay informed about potential vulnerabilities and threats and adjust its risk management strategies accordingly. o Without the ability to receive updates, a device cannot be secured against emerging threats, making it a liability to the organization's security posture.
Shaman73 👍 2
• C. Recurring

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Recurring risk assessments are explicitly designed to occur at predefined, regular intervals such as annually, quarterly, or semi-annually. An annual requirement mandates that the organization repeatedly evaluates its risk posture on a fixed yearly calendar, ensuring ongoing compliance and updated threat awareness.

Why the Other Options Are Wrong

Continuous assessments involve real-time or near-real-time monitoring tools that operate without interruption, which contradicts the scheduled nature of an annual review. Ad hoc assessments are initiated reactively in response to specific incidents, mergers, or emerging threats rather than a fixed calendar. One-time assessments are conducted solely for initial baseline establishment or project completion, lacking any inherent requirement for future repetition.

Community Comment Notes

The voting distribution shows unanimous agreement on option C, reflecting strong topic clarity among candidates. Comment [2] provides an excellent breakdown by eliminating distractors through direct keyword analysis, noting that ad hoc is reactive and one-time lacks repetition. Comment [1] reinforces the operational value of recurring assessments, emphasizing how scheduled reviews maintain proactive vulnerability management over time.

Exam Strategy

When encountering governance and compliance questions, immediately map temporal keywords to their corresponding control types; phrases like annual, monthly, or scheduled always indicate recurring processes. Train yourself to spot trigger words such as reactive, incident-specific, or real-time to quickly eliminate ad hoc and continuous distractors during timed exams.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide