210-250 · Question #143
Which purpose of a security risk assessment is true?
The correct answer is A. Find implementation issues that could lead to vulnerability. A security risk assessment identifies implementation weaknesses and potential vulnerabilities in systems before they can be exploited.
Question
Which purpose of a security risk assessment is true?
Options
- AFind implementation issues that could lead to vulnerability
- BNotify the customer of a vulnerability
- CSet the SIR value of a vulnerability
- DScore a vulnerability
How the community answered
(28 responses)- A89% (25)
- C7% (2)
- D4% (1)
Why each option
A security risk assessment identifies implementation weaknesses and potential vulnerabilities in systems before they can be exploited.
The primary purpose of a security risk assessment is to systematically examine systems, configurations, and processes to uncover implementation flaws - such as misconfigurations, missing patches, or weak controls - that could introduce exploitable vulnerabilities, enabling the organization to remediate them proactively.
Notifying customers of discovered vulnerabilities is a disclosure or remediation step that occurs after the assessment is complete, not the assessment's defining purpose.
Assigning a Security Impact Rating (SIR) value is part of the vulnerability scoring or triage process performed during vulnerability management, not the purpose of a risk assessment.
Scoring a vulnerability using frameworks like CVSS is a vulnerability management activity performed after discovery, not the objective of conducting a risk assessment.
Concept tested: Purpose and scope of security risk assessments
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.