nerdexam
(ISC)2

CAP · Question #241

Which of the following RMF phases is known as risk analysis?

The correct answer is C. Phase 2. The Risk Management Framework (RMF) used in U.S. federal information security consists of multiple phases. Phase 2 is specifically known as the Risk Analysis phase, where threats and vulnerabilities are identified and analyzed to determine the likelihood and potential impact of…

Selection and Approval of Framework, Security, and Privacy Controls

Question

Which of the following RMF phases is known as risk analysis?

Options

  • APhase 0
  • BPhase 1
  • CPhase 2
  • DPhase 3

How the community answered

(67 responses)
  • A
    1% (1)
  • B
    3% (2)
  • C
    90% (60)
  • D
    6% (4)

Explanation

The Risk Management Framework (RMF) used in U.S. federal information security consists of multiple phases. Phase 2 is specifically known as the Risk Analysis phase, where threats and vulnerabilities are identified and analyzed to determine the likelihood and potential impact of adverse events. Phase 0 is typically the pre-assessment/preparation phase, Phase 1 is System Characterization (identifying the system boundaries, hardware, software, and data), and Phase 3 involves control selection and implementation. Risk analysis (Phase 2) forms the core analytical step where quantitative or qualitative assessments are made to prioritize risks.

Topics

#RMF Phases#NIST RMF#Risk Analysis#Control Selection

Community Discussion

No community discussion yet for this question.

Full CAP Practice