nerdexam
EC-Council

712-50 · Question #17

What is the SECOND step to creating a risk management methodology according to the National Institute of Standards and Technology (NIST) SP 800-30 standard?

The correct answer is C. Perform a risk assessment. Performing a risk assessment (C) is the second step in the NIST SP 800-30 risk management process because the framework follows a four-step sequence: Frame → Assess → Respond → Monitor. After establishing the risk context (framing), the next logical action is to assess what…

Security Program Management & Operations

Question

What is the SECOND step to creating a risk management methodology according to the National Institute of Standards and Technology (NIST) SP 800-30 standard?

Options

  • ADetermine appetite
  • BEvaluate risk avoidance criteria
  • CPerform a risk assessment
  • DMitigate risk

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    84% (21)
  • D
    4% (1)

Explanation

Performing a risk assessment (C) is the second step in the NIST SP 800-30 risk management process because the framework follows a four-step sequence: Frame → Assess → Respond → Monitor. After establishing the risk context (framing), the next logical action is to assess what risks actually exist before any decisions can be made.

Why the distractors are wrong:

  • A (Determine appetite) - Risk appetite is established during the first step (Frame risk), where organizational context and risk tolerance are defined before any assessment occurs.
  • B (Evaluate risk avoidance criteria) - Avoidance is a response strategy, not a standalone step; it belongs in the third step (Respond to risk), and the phrasing doesn't match any NIST-defined step.
  • D (Mitigate risk) - Mitigation is also a response strategy that comes in the third step, after you've already identified and assessed the risks.

Memory tip: Use the acronym FARM - Frame, Assess, Respond, Monitor. The second letter is A, so the second step is always Assess (perform a risk assessment). You can't respond to risks you haven't assessed yet.

Topics

#NIST SP 800-30#Risk Assessment#Risk Management Methodology#Risk Framework

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice