What Type of Risk Assessment Is Performed Annually?
A company is required to perform a risk assessment on an annual basis. Which of the following types of risk assessments does this requirement describe?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the ability to map assessment schedules to their correct operational categories, with the primary trap being the confusion between periodic cycles and singular or constant execution.
This question evaluates understanding of risk assessment scheduling frequencies within security governance frameworks. Community consensus confirms that annual evaluations are definitively classified as recurring assessments due to their structured, periodic nature.
One time: Test-takers frequently misread annual as a standalone event rather than a repeating yearly obligation, failing to recognize the cyclical mandate embedded in the scenario.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Recurring risk assessments are explicitly designed to occur at predefined, regular intervals such as annually, quarterly, or semi-annually. An annual requirement mandates that the organization repeatedly evaluates its risk posture on a fixed yearly calendar, ensuring ongoing compliance and updated threat awareness.Why the Other Options Are Wrong
Continuous assessments involve real-time or near-real-time monitoring tools that operate without interruption, which contradicts the scheduled nature of an annual review. Ad hoc assessments are initiated reactively in response to specific incidents, mergers, or emerging threats rather than a fixed calendar. One-time assessments are conducted solely for initial baseline establishment or project completion, lacking any inherent requirement for future repetition.Community Comment Notes
The voting distribution shows unanimous agreement on option C, reflecting strong topic clarity among candidates. Comment [2] provides an excellent breakdown by eliminating distractors through direct keyword analysis, noting that ad hoc is reactive and one-time lacks repetition. Comment [1] reinforces the operational value of recurring assessments, emphasizing how scheduled reviews maintain proactive vulnerability management over time.Exam Strategy
When encountering governance and compliance questions, immediately map temporal keywords to their corresponding control types; phrases like annual, monthly, or scheduled always indicate recurring processes. Train yourself to spot trigger words such as reactive, incident-specific, or real-time to quickly eliminate ad hoc and continuous distractors during timed exams.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →