nerdexam
CompTIA

CAS-001 · Question #280

Denise works as a Security Administrator for a community college. She is assessing the various risks to her network. Which of the following is not a category of risk assessment?

The correct answer is C. Cost determination. Cost determination is a financial analysis activity associated with control selection, not a recognized category within a formal risk assessment methodology.

Research and Analysis

Question

Denise works as a Security Administrator for a community college. She is assessing the various risks to her network. Which of the following is not a category of risk assessment?

Options

  • ALikelihood assessment
  • BRisk determination
  • CCost determination
  • DVulnerability assessment

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    90% (37)
  • D
    5% (2)

Why each option

Cost determination is a financial analysis activity associated with control selection, not a recognized category within a formal risk assessment methodology.

ALikelihood assessment

Likelihood assessment is a core risk assessment category that estimates the probability a threat will successfully exploit a given vulnerability.

BRisk determination

Risk determination is the synthesizing step in risk assessment where likelihood and impact ratings are combined to assign an overall risk level to a finding.

CCost determinationCorrect

Standard risk assessment frameworks such as NIST SP 800-30 define assessment categories including threat identification, vulnerability assessment, likelihood assessment, impact assessment, and risk determination - but cost determination is not among them. Cost analysis belongs to the risk response phase, where the cost-effectiveness of proposed countermeasures is weighed after risks have been identified and rated. Including cost as a risk assessment category conflates risk identification with risk treatment activities.

DVulnerability assessment

Vulnerability assessment is a foundational component of risk assessment that systematically identifies weaknesses in systems, processes, or controls that threats could exploit.

Concept tested: Risk assessment categories per NIST SP 800-30

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#risk assessment#risk management#vulnerability assessment#risk categories

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice