nerdexam
EC-Council

212-89 · Question #118

Andrew, an incident responder, is performing risk assessment of the client organization. As a part of risk assessment process, he identified the boundaries of the IT systems, along with the…

The correct answer is B. System characterization. In the risk assessment process, "System characterization" is the initial step where the scope of the assessment is defined. This involves identifying and documenting the boundaries of the IT systems under review, the resources (hardware, software, data, and personnel) that…

Incident Handling and Response Planning

Question

Andrew, an incident responder, is performing risk assessment of the client organization. As a part of risk assessment process, he identified the boundaries of the IT systems, along with the resources and the information that constitute the systems. Identify the risk assessment step Andrew is performing.

Options

  • AControl analysis
  • BSystem characterization
  • CLikelihood determination
  • DControl recommendations

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    95% (36)
  • D
    3% (1)

Explanation

In the risk assessment process, "System characterization" is the initial step where the scope of the assessment is defined. This involves identifying and documenting the boundaries of the IT systems under review, the resources (hardware, software, data, and personnel) that constitute these systems, and any relevant information about their operation and environment. This foundational step is essential for understanding what needs to be protected and forms the basis for subsequent analysis, including identifying vulnerabilities, assessing potential threats, and determining the impact of risks to the organization.

Topics

#risk assessment#system characterization#IT boundary identification#NIST risk framework

Community Discussion

No community discussion yet for this question.

Full 212-89 Practice