nerdexam
EC-Council

312-50V11 · Question #558

What information should an IT system analysis provide to the risk assessor?

The correct answer is C. Security architecture. IT system analysis feeds the risk assessor information about the current security architecture, including controls and configurations already in place.

Information Security and Ethical Hacking Fundamentals

Question

What information should an IT system analysis provide to the risk assessor?

Options

  • AManagement buy-in
  • BThreat statement
  • CSecurity architecture
  • DImpact analysis

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    89% (33)
  • D
    3% (1)

Why each option

IT system analysis feeds the risk assessor information about the current security architecture, including controls and configurations already in place.

AManagement buy-in

Management buy-in is an organizational prerequisite for conducting a risk assessment, not an output of IT system analysis.

BThreat statement

A threat statement is produced during the threat identification phase of the risk assessment itself, not derived from system analysis.

CSecurity architectureCorrect

An IT system analysis documents the security architecture of the target system, including its components, existing security controls, data flows, and configurations. This information is essential for the risk assessor to understand the current security posture and identify gaps. Without this architectural baseline, a meaningful risk assessment cannot be performed.

DImpact analysis

Impact analysis is a separate step in the risk assessment process that evaluates consequences of threats, not an output of system analysis.

Concept tested: IT system analysis output in risk assessment

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#risk assessment#security architecture#IT analysis#information systems

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice