nerdexam
EC-Council

312-50V9 · Question #454

Which of the following is a component of a risk assessment?

The correct answer is B. Administrative safeguards. Risk assessments evaluate existing safeguards and controls, including administrative safeguards, making it the component that belongs in a risk assessment.

Vulnerability Analysis

Question

Which of the following is a component of a risk assessment?

Options

  • APhysical security
  • BAdministrative safeguards
  • CDMZ
  • DLogical interface

How the community answered

(54 responses)
  • A
    2% (1)
  • B
    93% (50)
  • C
    2% (1)
  • D
    4% (2)

Why each option

Risk assessments evaluate existing safeguards and controls, including administrative safeguards, making it the component that belongs in a risk assessment.

APhysical security

Physical security is a category of security control, not a component of a risk assessment methodology.

BAdministrative safeguardsCorrect

Administrative safeguards are policies, procedures, and management actions that govern the selection and implementation of security measures, and they are formally evaluated as part of a risk assessment to determine whether existing controls adequately address identified threats and vulnerabilities. NIST SP 800-30 specifically includes reviewing administrative controls as a step in the risk assessment process. Identifying gaps in administrative safeguards informs the overall risk determination.

CDMZ

A DMZ is a network architecture element and technical control, not a component of the risk assessment process itself.

DLogical interface

A logical interface is a networking or system concept, not a defined component within a risk assessment framework.

Concept tested: Risk assessment components and administrative safeguards

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#risk assessment#administrative safeguards#risk management#security controls

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice