712-50 · Question #194
Which of the following functions evaluates risk present in IT initiatives and/or systems when implementing an information security program?
The correct answer is B. Risk Assessment. Risk Assessment (B) is the function specifically designed to evaluate risk present in IT initiatives and systems - it identifies threats, vulnerabilities, and their potential impact, which is exactly what the question asks about. Risk Management (A) is broader; it encompasses…
Question
Which of the following functions evaluates risk present in IT initiatives and/or systems when implementing an information security program?
Options
- ARisk Management
- BRisk Assessment
- CSystem Testing
- DVulnerability Assessment
How the community answered
(40 responses)- A13% (5)
- B80% (32)
- C3% (1)
- D5% (2)
Explanation
Risk Assessment (B) is the function specifically designed to evaluate risk present in IT initiatives and systems - it identifies threats, vulnerabilities, and their potential impact, which is exactly what the question asks about.
Risk Management (A) is broader; it encompasses the entire process of identifying, assessing, and responding to risk (including mitigation, transfer, and acceptance) - it's the overarching program, not the evaluation step itself.
System Testing (C) verifies that a system functions as intended; while it may surface defects, it is not a risk evaluation function and is not specific to information security risk.
Vulnerability Assessment (D) is a close distractor - it identifies weaknesses in systems, but it focuses narrowly on technical vulnerabilities rather than evaluating the broader risk (likelihood × impact) associated with IT initiatives.
Memory tip: Think of the word "assess" = "evaluate." The question uses the word evaluates, which maps directly to assessment. Risk Assessment = evaluate risk; Risk Management = handle risk.
Topics
Community Discussion
No community discussion yet for this question.