nerdexam
EC-Council

312-50V9 · Question #451

Which of the following lists are valid data-gathering activities associated with a risk assessment?

The correct answer is A. Threat identification, vulnerability identification, control analysis. A risk assessment's data-gathering phase standardly includes identifying threats, identifying vulnerabilities, and analyzing existing controls - as defined by NIST SP 800-30.

Vulnerability Analysis

Question

Which of the following lists are valid data-gathering activities associated with a risk assessment?

Options

  • AThreat identification, vulnerability identification, control analysis
  • BThreat identification, response identification, mitigation identification
  • CAttack profile, defense profile, loss profile
  • DSystem profile, vulnerability identification, security determination

How the community answered

(42 responses)
  • A
    88% (37)
  • B
    2% (1)
  • C
    7% (3)
  • D
    2% (1)

Why each option

A risk assessment's data-gathering phase standardly includes identifying threats, identifying vulnerabilities, and analyzing existing controls - as defined by NIST SP 800-30.

AThreat identification, vulnerability identification, control analysisCorrect

Threat identification, vulnerability identification, and control analysis are the three core data-gathering steps outlined in NIST SP 800-30. Threat identification determines what can go wrong, vulnerability identification finds weaknesses that threats can exploit, and control analysis evaluates existing safeguards to determine their adequacy.

BThreat identification, response identification, mitigation identification

Response identification and mitigation identification are activities associated with risk response planning, not the initial data-gathering phase of a risk assessment.

CAttack profile, defense profile, loss profile

Attack profile, defense profile, and loss profile are not standard NIST or ISO risk assessment data-gathering categories.

DSystem profile, vulnerability identification, security determination

While system profiling and vulnerability identification are valid steps, 'security determination' is not a defined data-gathering activity; it conflates analysis with the later risk determination phase.

Concept tested: NIST SP 800-30 risk assessment data-gathering steps

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#risk assessment#threat identification#vulnerability identification#control analysis

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice