nerdexam
EC-Council

712-50 · Question #134

During the course of a risk analysis your IT auditor identified threats and potential impacts. Next, your IT auditor should:

The correct answer is A. Identify and evaluate the existing controls. Why A is correct: Risk analysis follows a structured sequence: identify assets → identify threats and impacts → evaluate existing controls → assess residual risk. After identifying threats and impacts, the logical next step is to understand what controls are already in place…

IS Management Controls and Auditing Management

Question

During the course of a risk analysis your IT auditor identified threats and potential impacts. Next, your IT auditor should:

Options

  • AIdentify and evaluate the existing controls.
  • BDisclose the threats and impacts to management.
  • CIdentify information assets and the underlying systems.
  • DIdentify and assess the risk assessment process used by management.

How the community answered

(57 responses)
  • A
    77% (44)
  • B
    4% (2)
  • C
    5% (3)
  • D
    14% (8)

Explanation

Why A is correct: Risk analysis follows a structured sequence: identify assets → identify threats and impacts → evaluate existing controls → assess residual risk. After identifying threats and impacts, the logical next step is to understand what controls are already in place before recommending new ones - you can't determine gaps without knowing what defenses exist.

Why the distractors are wrong:

  • B is premature - disclosing to management happens after the full risk assessment is complete, not mid-process.
  • C is a prior step - identifying information assets and underlying systems should have already occurred before identifying threats and impacts.
  • D is a separate audit activity (auditing the risk process itself), not part of executing a risk analysis.

Memory tip: Think of the risk analysis sequence as A-T-C-R: Assets → Threats/Impacts → Controls → Residual Risk. You're always one step ahead - assets come before threats, and controls come right after threats. If the question tells you "threats identified," the next step is always "controls evaluated."

Topics

#Risk Analysis#Controls Assessment#Audit Methodology#Risk Management

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice