100-160 · Question #32
Drag and Drop Question You need to manage security risks at your company. In which order should you complete the actions? Move all the actions to the answer area and place them in the correct order…
The correct answer is Identify the risks.; Prioritize the risks.; Implement a response.; Monitor results. Security Risk Management: Correct Order Explained The correct sequence follows the standard risk management lifecycle, used in frameworks like NIST, ISO 27001, and CompTIA Security+. --- 1. Identify the Risks Why first: You cannot manage what you don't know exists. This step…
Question
Drag and Drop Question You need to manage security risks at your company. In which order should you complete the actions? Move all the actions to the answer area and place them in the correct order. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- Identify the risks.
- Prioritize the risks.
- Implement a response.
- Monitor results.
Explanation
Security Risk Management: Correct Order Explained
The correct sequence follows the standard risk management lifecycle, used in frameworks like NIST, ISO 27001, and CompTIA Security+.
1. Identify the Risks
Why first: You cannot manage what you don't know exists. This step involves discovering threats, vulnerabilities, and assets at risk - through audits, assessments, and threat modeling. Everything downstream depends on this inventory.
2. Prioritize the Risks
Why second: Not all risks are equal. After identification, you assess each risk by likelihood × impact to produce a risk score. This determines where to focus limited time and budget. Acting before prioritizing leads to wasted effort on low-impact threats while critical ones go unaddressed.
Common mistake: Jumping straight to implementing responses before prioritizing. This is a classic error - teams patch the most recently discovered issue rather than the most dangerous one.
3. Implement a Response
Why third: Only after knowing what risks exist and which matter most do you act. Responses include mitigating, accepting, transferring (insurance), or avoiding the risk. Implementing without the prior steps means flying blind.
Common mistake: Treating this as the final step. Many people stop here, which is wrong - implementation without follow-up leaves you unable to confirm it worked.
4. Monitor Results
Why last: You must verify that your response actually reduced the risk, watch for new risks emerging, and ensure controls remain effective over time. Risk management is a continuous cycle, not a one-time task.
The Core Mental Model
Identify → Prioritize → Respond → Monitor → (repeat)
This mirrors the Plan-Do-Check-Act (PDCA) cycle and is consistent across all major security frameworks. The ordering is logical: you must know before you rank, rank before you act, act before you verify.
Topics
Community Discussion
No community discussion yet for this question.
