712-50 · Question #29
Which of the following lists are valid data-gathering activities associated with a risk assessment?
The correct answer is A. Threat identification, vulnerability identification, control analysis. Option A is correct because threat identification, vulnerability identification, and control analysis are the three canonical data-gathering activities defined in NIST SP 800-30 and similar risk assessment frameworks - you identify what threats exist, what weaknesses can be…
Question
Which of the following lists are valid data-gathering activities associated with a risk assessment?
Options
- AThreat identification, vulnerability identification, control analysis
- BThreat identification, response identification, mitigation identification
- CAttack profile, defense profile, loss profile
- DSystem profile, vulnerability identification, security determination
How the community answered
(20 responses)- A80% (16)
- B5% (1)
- C10% (2)
- D5% (1)
Explanation
Option A is correct because threat identification, vulnerability identification, and control analysis are the three canonical data-gathering activities defined in NIST SP 800-30 and similar risk assessment frameworks - you identify what threats exist, what weaknesses can be exploited, and what controls are already in place. Option B is wrong because "response identification" and "mitigation identification" are risk response activities that happen after the assessment, not during data gathering. Option C uses informal terms ("attack profile," "defense profile," "loss profile") that don't correspond to any standard risk assessment methodology. Option D is partially correct - system profiling and vulnerability identification are legitimate steps - but "security determination" is a vague outcome, not a data-gathering activity; the framework calls for control analysis at that stage, not a final determination.
Memory tip: Think T-V-C - Threats, Vulnerabilities, Controls - as the three things you must gather data on before you can assess risk. Threats without controls or vulnerabilities without threats both give you an incomplete picture.
Topics
Community Discussion
No community discussion yet for this question.