nerdexam
(ISC)2

CERTIFIED-IN-CYBERSECURITY · Question #69

Risk Management is:

The correct answer is D. The identification, evaluation and prioritization of risks. Risk Management is the process of identifying, assessing and mitigating risks (ISC2 Study Guide, chapter 1, module 2). "Impact and likelihood of a threat" is a definition of risk. "Creating an incident response team" and "assessing the potential impact of a threat" can be…

Security Principles

Question

Risk Management is:

Options

  • AThe assessment of the potential impact of a threat
  • BThe impact and likelihood of a threat
  • CThe creation of an incident response team
  • DThe identification, evaluation and prioritization of risks

How the community answered

(42 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    7% (3)
  • D
    88% (37)

Explanation

Risk Management is the process of identifying, assessing and mitigating risks (ISC2 Study Guide, chapter 1, module 2). "Impact and likelihood of a threat" is a definition of risk. "Creating an incident response team" and "assessing the potential impact of a threat" can be considered Risk Management actions, but are not in themselves Risk Management.

Topics

#Risk Management#Cybersecurity Fundamentals#Risk Assessment

Community Discussion

No community discussion yet for this question.

Full CERTIFIED-IN-CYBERSECURITY Practice