nerdexam
EC-Council

712-50 · Question #194

Which of the following functions evaluates risk present in IT initiatives and/or systems when implementing an information security program?

The correct answer is B. Risk Assessment. Risk Assessment (B) is the function specifically designed to evaluate risk present in IT initiatives and systems - it identifies threats, vulnerabilities, and their potential impact, which is exactly what the question asks about. Risk Management (A) is broader; it encompasses…

Security Program Management & Operations

Question

Which of the following functions evaluates risk present in IT initiatives and/or systems when implementing an information security program?

Options

  • ARisk Management
  • BRisk Assessment
  • CSystem Testing
  • DVulnerability Assessment

How the community answered

(40 responses)
  • A
    13% (5)
  • B
    80% (32)
  • C
    3% (1)
  • D
    5% (2)

Explanation

Risk Assessment (B) is the function specifically designed to evaluate risk present in IT initiatives and systems - it identifies threats, vulnerabilities, and their potential impact, which is exactly what the question asks about.

Risk Management (A) is broader; it encompasses the entire process of identifying, assessing, and responding to risk (including mitigation, transfer, and acceptance) - it's the overarching program, not the evaluation step itself.

System Testing (C) verifies that a system functions as intended; while it may surface defects, it is not a risk evaluation function and is not specific to information security risk.

Vulnerability Assessment (D) is a close distractor - it identifies weaknesses in systems, but it focuses narrowly on technical vulnerabilities rather than evaluating the broader risk (likelihood × impact) associated with IT initiatives.

Memory tip: Think of the word "assess" = "evaluate." The question uses the word evaluates, which maps directly to assessment. Risk Assessment = evaluate risk; Risk Management = handle risk.

Topics

#risk assessment#risk evaluation#information security program#IT systems

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice