nerdexam
Cisco

100-160 · Question #32

Drag and Drop Question You need to manage security risks at your company. In which order should you complete the actions? Move all the actions to the answer area and place them in the correct order…

The correct answer is Identify the risks.; Prioritize the risks.; Implement a response.; Monitor results. Security Risk Management: Correct Order Explained The correct sequence follows the standard risk management lifecycle, used in frameworks like NIST, ISO 27001, and CompTIA Security+. --- 1. Identify the Risks Why first: You cannot manage what you don't know exists. This step…

Security Principles

Question

Drag and Drop Question You need to manage security risks at your company. In which order should you complete the actions? Move all the actions to the answer area and place them in the correct order. Answer:

Exhibit

100-160 question #32 exhibit

Answer Area

Drag items

Prioritize the risks.Implement a response.Monitor results.Identify the risks.

Correct arrangement

  • Identify the risks.
  • Prioritize the risks.
  • Implement a response.
  • Monitor results.

Explanation

Security Risk Management: Correct Order Explained

The correct sequence follows the standard risk management lifecycle, used in frameworks like NIST, ISO 27001, and CompTIA Security+.


1. Identify the Risks

Why first: You cannot manage what you don't know exists. This step involves discovering threats, vulnerabilities, and assets at risk - through audits, assessments, and threat modeling. Everything downstream depends on this inventory.


2. Prioritize the Risks

Why second: Not all risks are equal. After identification, you assess each risk by likelihood × impact to produce a risk score. This determines where to focus limited time and budget. Acting before prioritizing leads to wasted effort on low-impact threats while critical ones go unaddressed.

Common mistake: Jumping straight to implementing responses before prioritizing. This is a classic error - teams patch the most recently discovered issue rather than the most dangerous one.


3. Implement a Response

Why third: Only after knowing what risks exist and which matter most do you act. Responses include mitigating, accepting, transferring (insurance), or avoiding the risk. Implementing without the prior steps means flying blind.

Common mistake: Treating this as the final step. Many people stop here, which is wrong - implementation without follow-up leaves you unable to confirm it worked.


4. Monitor Results

Why last: You must verify that your response actually reduced the risk, watch for new risks emerging, and ensure controls remain effective over time. Risk management is a continuous cycle, not a one-time task.


The Core Mental Model

Identify → Prioritize → Respond → Monitor → (repeat)

This mirrors the Plan-Do-Check-Act (PDCA) cycle and is consistent across all major security frameworks. The ordering is logical: you must know before you rank, rank before you act, act before you verify.

Topics

#risk management#risk assessment#security governance#risk treatment

Community Discussion

No community discussion yet for this question.

Full 100-160 Practice