nerdexam
EC-Council

312-50V10 · Question #567

Which of the following lists are valid data-gathering activities associated with a risk assessment?

The correct answer is A. Threat identification, vulnerability identification, control analysis. Risk assessments follow a structured data-gathering process; the correct set of activities includes threat identification, vulnerability identification, and control analysis as defined in standard risk assessment frameworks like NIST SP 800-30.

Information Security and Ethical Hacking Fundamentals

Question

Which of the following lists are valid data-gathering activities associated with a risk assessment?

Options

  • AThreat identification, vulnerability identification, control analysis
  • BThreat identification, response identification, mitigation identification
  • CAttack profile, defense profile, loss profile
  • DSystem profile, vulnerability identification, security determination

How the community answered

(25 responses)
  • A
    96% (24)
  • C
    4% (1)

Why each option

Risk assessments follow a structured data-gathering process; the correct set of activities includes threat identification, vulnerability identification, and control analysis as defined in standard risk assessment frameworks like NIST SP 800-30.

AThreat identification, vulnerability identification, control analysisCorrect

Threat identification, vulnerability identification, and control analysis are the three core data-gathering activities in the NIST SP 800-30 risk assessment process. Threat identification catalogs what can cause harm, vulnerability identification finds weaknesses that could be exploited, and control analysis inventories existing safeguards. Together these three steps provide the raw data needed to calculate likelihood and impact.

BThreat identification, response identification, mitigation identification

Response identification and mitigation identification are risk treatment and response planning activities, not data-gathering steps performed during the assessment phase.

CAttack profile, defense profile, loss profile

Attack profile, defense profile, and loss profile are not standard data-gathering activities recognized in any major risk assessment methodology.

DSystem profile, vulnerability identification, security determination

While system profiling and vulnerability identification are valid data-gathering steps, 'security determination' is a concluding or decision-making step rather than a data-gathering activity, making this list inaccurate.

Concept tested: NIST SP 800-30 risk assessment data-gathering steps

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#risk assessment#threat identification#vulnerability identification#control analysis

Community Discussion

No community discussion yet for this question.

Full 312-50V10 Practice