nerdexam
(ISC)2

CGRC · Question #88

Which of the following BEST defines the purpose of security assessment? Response:

The correct answer is B. To determine the extent to which the security controls are implemented correctly and operating as. The best definition of security assessment is determining the extent to which security controls are correctly implemented, operating as intended, and producing the desired security outcomes.

Assessment/Audit of Security and Privacy Controls

Question

Which of the following BEST defines the purpose of security assessment? Response:

Options

  • ATo determine if the remaining known vulnerability pose an acceptable level of risk
  • BTo determine the extent to which the security controls are implemented correctly and operating as
  • CTo perform oversight and monitor the security controls in the information system (IS)
  • DTo perform initial risk estimate and security categorization of the information system (IS)

How the community answered

(45 responses)
  • A
    2% (1)
  • B
    89% (40)
  • C
    2% (1)
  • D
    7% (3)

Why each option

The best definition of security assessment is determining the extent to which security controls are correctly implemented, operating as intended, and producing the desired security outcomes.

ATo determine if the remaining known vulnerability pose an acceptable level of risk

While assessments inform risk decisions, determining an "acceptable level of risk" is the responsibility of the Authorizing Official during the Authorize step, not the primary purpose of the assessment itself.

BTo determine the extent to which the security controls are implemented correctly and operating asCorrect

Security assessment, particularly within frameworks like NIST RMF, is a systematic process of evaluating the effectiveness of security controls. This evaluation focuses on whether the controls are implemented accurately, functioning reliably as designed, and achieving the intended security objectives to protect the information system and its data.

CTo perform oversight and monitor the security controls in the information system (IS)

Performing oversight and monitoring is the purpose of the Monitor step (Step 6), which follows assessment, not the assessment itself.

DTo perform initial risk estimate and security categorization of the information system (IS)

Performing initial risk estimation and security categorization is part of the Categorize step (Step 1), which occurs at the very beginning of the RMF process, not during assessment.

Concept tested: Security assessment purpose and scope

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Security Assessment#Control Assessment#Security Controls#Purpose

Community Discussion

No community discussion yet for this question.

Full CGRC Practice