nerdexam
(ISC)2

CAP · Question #157

Which of the following are the goals of risk management? Each correct answer represents a complete solution. Choose three.

The correct answer is A. Finding an economic balance between the impact of the risk and the cost of the counterme B. Identifying the risk C. Assessing the impact of potential threats. The three recognized goals of risk management are identifying risks, assessing threat impact, and balancing risk impact against countermeasure cost - not identifying accused individuals.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following are the goals of risk management? Each correct answer represents a complete solution. Choose three.

Options

  • AFinding an economic balance between the impact of the risk and the cost of the counterme
  • BIdentifying the risk
  • CAssessing the impact of potential threats
  • DIdentifying the accused

How the community answered

(59 responses)
  • A
    93% (55)
  • D
    7% (4)

Why each option

The three recognized goals of risk management are identifying risks, assessing threat impact, and balancing risk impact against countermeasure cost - not identifying accused individuals.

AFinding an economic balance between the impact of the risk and the cost of the countermeCorrect

Finding an economic balance between the impact of a risk and the cost of a countermeasure is a fundamental risk management goal, ensuring that security investments are proportional and justified relative to the threats they address.

BIdentifying the riskCorrect

Identifying risks is the foundational goal of risk management; without formally identifying risks, they cannot be assessed, prioritized, or treated.

CAssessing the impact of potential threatsCorrect

Assessing the impact and likelihood of potential threats enables organizations to prioritize risks and allocate limited resources to the most significant exposures.

DIdentifying the accused

Identifying an accused person is a forensic investigation or legal process objective, not a risk management goal; risk management focuses on threats and vulnerabilities, not attribution of blame to individuals.

Concept tested: Core goals and objectives of risk management

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#Risk Management Goals#Risk Identification#Risk Assessment#Cost-Benefit Analysis

Community Discussion

No community discussion yet for this question.

Full CAP Practice