CAP · Question #241
Which of the following RMF phases is known as risk analysis?
The correct answer is C. Phase 2. The Risk Management Framework (RMF) used in U.S. federal information security consists of multiple phases. Phase 2 is specifically known as the Risk Analysis phase, where threats and vulnerabilities are identified and analyzed to determine the likelihood and potential impact of…
Question
Which of the following RMF phases is known as risk analysis?
Options
- APhase 0
- BPhase 1
- CPhase 2
- DPhase 3
How the community answered
(67 responses)- A1% (1)
- B3% (2)
- C90% (60)
- D6% (4)
Explanation
The Risk Management Framework (RMF) used in U.S. federal information security consists of multiple phases. Phase 2 is specifically known as the Risk Analysis phase, where threats and vulnerabilities are identified and analyzed to determine the likelihood and potential impact of adverse events. Phase 0 is typically the pre-assessment/preparation phase, Phase 1 is System Characterization (identifying the system boundaries, hardware, software, and data), and Phase 3 involves control selection and implementation. Risk analysis (Phase 2) forms the core analytical step where quantitative or qualitative assessments are made to prioritize risks.
Topics
Community Discussion
No community discussion yet for this question.