312-50V9 · Question #454
Which of the following is a component of a risk assessment?
The correct answer is B. Administrative safeguards. Risk assessments evaluate existing safeguards and controls, including administrative safeguards, making it the component that belongs in a risk assessment.
Question
Which of the following is a component of a risk assessment?
Options
- APhysical security
- BAdministrative safeguards
- CDMZ
- DLogical interface
How the community answered
(54 responses)- A2% (1)
- B93% (50)
- C2% (1)
- D4% (2)
Why each option
Risk assessments evaluate existing safeguards and controls, including administrative safeguards, making it the component that belongs in a risk assessment.
Physical security is a category of security control, not a component of a risk assessment methodology.
Administrative safeguards are policies, procedures, and management actions that govern the selection and implementation of security measures, and they are formally evaluated as part of a risk assessment to determine whether existing controls adequately address identified threats and vulnerabilities. NIST SP 800-30 specifically includes reviewing administrative controls as a step in the risk assessment process. Identifying gaps in administrative safeguards informs the overall risk determination.
A DMZ is a network architecture element and technical control, not a component of the risk assessment process itself.
A logical interface is a networking or system concept, not a defined component within a risk assessment framework.
Concept tested: Risk assessment components and administrative safeguards
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.