nerdexam
EC-Council

712-50 · Question #29

Which of the following lists are valid data-gathering activities associated with a risk assessment?

The correct answer is A. Threat identification, vulnerability identification, control analysis. Option A is correct because threat identification, vulnerability identification, and control analysis are the three canonical data-gathering activities defined in NIST SP 800-30 and similar risk assessment frameworks - you identify what threats exist, what weaknesses can be…

IS Management Controls and Auditing Management

Question

Which of the following lists are valid data-gathering activities associated with a risk assessment?

Options

  • AThreat identification, vulnerability identification, control analysis
  • BThreat identification, response identification, mitigation identification
  • CAttack profile, defense profile, loss profile
  • DSystem profile, vulnerability identification, security determination

How the community answered

(20 responses)
  • A
    80% (16)
  • B
    5% (1)
  • C
    10% (2)
  • D
    5% (1)

Explanation

Option A is correct because threat identification, vulnerability identification, and control analysis are the three canonical data-gathering activities defined in NIST SP 800-30 and similar risk assessment frameworks - you identify what threats exist, what weaknesses can be exploited, and what controls are already in place. Option B is wrong because "response identification" and "mitigation identification" are risk response activities that happen after the assessment, not during data gathering. Option C uses informal terms ("attack profile," "defense profile," "loss profile") that don't correspond to any standard risk assessment methodology. Option D is partially correct - system profiling and vulnerability identification are legitimate steps - but "security determination" is a vague outcome, not a data-gathering activity; the framework calls for control analysis at that stage, not a final determination.

Memory tip: Think T-V-C - Threats, Vulnerabilities, Controls - as the three things you must gather data on before you can assess risk. Threats without controls or vulnerabilities without threats both give you an incomplete picture.

Topics

#Risk Assessment#Threat Identification#Vulnerability Analysis#Control Analysis

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice