312-50V10 · Question #567
Which of the following lists are valid data-gathering activities associated with a risk assessment?
The correct answer is A. Threat identification, vulnerability identification, control analysis. Risk assessments follow a structured data-gathering process; the correct set of activities includes threat identification, vulnerability identification, and control analysis as defined in standard risk assessment frameworks like NIST SP 800-30.
Question
Which of the following lists are valid data-gathering activities associated with a risk assessment?
Options
- AThreat identification, vulnerability identification, control analysis
- BThreat identification, response identification, mitigation identification
- CAttack profile, defense profile, loss profile
- DSystem profile, vulnerability identification, security determination
How the community answered
(25 responses)- A96% (24)
- C4% (1)
Why each option
Risk assessments follow a structured data-gathering process; the correct set of activities includes threat identification, vulnerability identification, and control analysis as defined in standard risk assessment frameworks like NIST SP 800-30.
Threat identification, vulnerability identification, and control analysis are the three core data-gathering activities in the NIST SP 800-30 risk assessment process. Threat identification catalogs what can cause harm, vulnerability identification finds weaknesses that could be exploited, and control analysis inventories existing safeguards. Together these three steps provide the raw data needed to calculate likelihood and impact.
Response identification and mitigation identification are risk treatment and response planning activities, not data-gathering steps performed during the assessment phase.
Attack profile, defense profile, and loss profile are not standard data-gathering activities recognized in any major risk assessment methodology.
While system profiling and vulnerability identification are valid data-gathering steps, 'security determination' is a concluding or decision-making step rather than a data-gathering activity, making this list inaccurate.
Concept tested: NIST SP 800-30 risk assessment data-gathering steps
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.