nerdexam
EC-Council

312-50V9 · Question #436

What information should an IT system analysis provide to the risk assessor?

The correct answer is C. Security architecture. An IT system analysis documents the technical security architecture of a system, giving the risk assessor the structural context needed to identify and evaluate risks.

Introduction to Ethical Hacking

Question

What information should an IT system analysis provide to the risk assessor?

Options

  • AManagement buy-in
  • BThreat statement
  • CSecurity architecture
  • DImpact analysis

How the community answered

(37 responses)
  • A
    3% (1)
  • C
    95% (35)
  • D
    3% (1)

Why each option

An IT system analysis documents the technical security architecture of a system, giving the risk assessor the structural context needed to identify and evaluate risks.

AManagement buy-in

Management buy-in is a prerequisite for conducting a risk assessment program, not an output that system analysis provides to the risk assessor.

BThreat statement

A threat statement is produced during the threat identification phase of the risk assessment itself, not derived from the IT system analysis.

CSecurity architectureCorrect

Security architecture describes the system's components, data flows, trust boundaries, and existing controls - precisely the technical picture a risk assessor needs to evaluate exposure. Without understanding how the system is designed and what protections are already in place, the assessor cannot accurately identify threats or determine risk levels. System analysis feeds architecture details into the risk assessment process as defined in NIST SP 800-30.

DImpact analysis

Impact analysis is performed by the risk assessor after receiving system information, not an input that system analysis supplies.

Concept tested: IT system analysis inputs to risk assessment

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#security architecture#risk assessment#IT system analysis#information security management

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice