nerdexam
(ISC)2

CAP · Question #14

Information risk management (IRM) is the process of identifying and assessing risk, reducing it to an acceptable level, and implementing the right mechanisms to maintain that level. What are the…

The correct answer is B. Human interaction C. Equipment malfunction D. Inside and outside attacks E. Social status F. Physical damage. Information Risk Management recognizes multiple categories of risk that can threaten information assets. These include: (B) Human interaction - errors or intentional misuse by people; (C) Equipment malfunction - hardware or software failures; (D) Inside and outside attacks…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Information risk management (IRM) is the process of identifying and assessing risk, reducing it to an acceptable level, and implementing the right mechanisms to maintain that level. What are the different categories of risk? Each correct answer represents a complete solution. Choose all that apply.

Options

  • ASystem interaction
  • BHuman interaction
  • CEquipment malfunction
  • DInside and outside attacks
  • ESocial status
  • FPhysical damage

How the community answered

(56 responses)
  • A
    11% (6)
  • B
    89% (50)

Explanation

Information Risk Management recognizes multiple categories of risk that can threaten information assets. These include: (B) Human interaction - errors or intentional misuse by people; (C) Equipment malfunction - hardware or software failures; (D) Inside and outside attacks - threats from internal users or external adversaries; (E) Social status - social engineering and social factors that create vulnerabilities; and (F) Physical damage - fire, flood, or environmental hazards. Choice A - 'System interaction' - is not a standard recognized category in IRM frameworks, making it the incorrect option.

Topics

#Risk Management#Risk Categories#Threat Sources#IRM

Community Discussion

No community discussion yet for this question.

Full CAP Practice