nerdexam
(ISC)2

CERTIFIED-IN-CYBERSECURITY · Question #163

Which of the following is NOT a part of 'Risk assessment'? ()

The correct answer is A. Risk mitigation. Risk assessment consists of three core phases: risk identification (C) - finding potential threats and vulnerabilities; risk evaluation/analysis (D) - determining likelihood and impact; and risk prioritization (B) - ranking risks by severity. Risk mitigation (A) is the act of…

Security Principles - Risk Management Concepts

Question

Which of the following is NOT a part of 'Risk assessment'? ()

Options

  • ARisk mitigation
  • BRisk prioritization
  • CRisk identification
  • DRisk evaluation

How the community answered

(37 responses)
  • A
    95% (35)
  • B
    3% (1)
  • C
    3% (1)

Explanation

Risk assessment consists of three core phases: risk identification (C) - finding potential threats and vulnerabilities; risk evaluation/analysis (D) - determining likelihood and impact; and risk prioritization (B) - ranking risks by severity. Risk mitigation (A) is the act of taking action to reduce or eliminate a risk, which belongs to the risk treatment or risk response phase - a separate process that follows risk assessment. Mitigation is an output of what you do after assessing risks, not part of the assessment itself.

Topics

#Risk Assessment#Risk Management#Cybersecurity Fundamentals#Security Principles

Community Discussion

No community discussion yet for this question.

Full CERTIFIED-IN-CYBERSECURITY Practice