CERTIFIED-IN-CYBERSECURITY · Question #163
Which of the following is NOT a part of 'Risk assessment'? ()
The correct answer is A. Risk mitigation. Risk assessment consists of three core phases: risk identification (C) - finding potential threats and vulnerabilities; risk evaluation/analysis (D) - determining likelihood and impact; and risk prioritization (B) - ranking risks by severity. Risk mitigation (A) is the act of…
Question
Which of the following is NOT a part of 'Risk assessment'? ()
Options
- ARisk mitigation
- BRisk prioritization
- CRisk identification
- DRisk evaluation
How the community answered
(37 responses)- A95% (35)
- B3% (1)
- C3% (1)
Explanation
Risk assessment consists of three core phases: risk identification (C) - finding potential threats and vulnerabilities; risk evaluation/analysis (D) - determining likelihood and impact; and risk prioritization (B) - ranking risks by severity. Risk mitigation (A) is the act of taking action to reduce or eliminate a risk, which belongs to the risk treatment or risk response phase - a separate process that follows risk assessment. Mitigation is an output of what you do after assessing risks, not part of the assessment itself.
Topics
Community Discussion
No community discussion yet for this question.