nerdexam
(ISC)2

CISSP-ISSMP · Question #120

Which of the following are the process steps of OPSEC? Each correct answer represents a part of the solution. Choose all that apply.

The correct answer is A. Analysis of Vulnerabilities C. Assessment of Risk D. Identification of Critical Information. The OPSEC process has five steps which are as follows. 1.Identification of Critical Information. Identifying information vitally needed by an adversary, which focuses the remainder of the OPSEC process on protecting vital information, rather than attempting to protect all…

Security Operations Management

Question

Which of the following are the process steps of OPSEC? Each correct answer represents a part of the solution. Choose all that apply.

Options

  • AAnalysis of Vulnerabilities
  • BDisplay of associated vulnerability components
  • CAssessment of Risk
  • DIdentification of Critical Information

How the community answered

(51 responses)
  • A
    86% (44)
  • B
    14% (7)

Explanation

The OPSEC process has five steps which are as follows. 1.Identification of Critical Information. Identifying information vitally needed by an adversary, which focuses the remainder of the OPSEC process on protecting vital information, rather than attempting to protect all classified or sensitive unclassified information. 2.Analysis of Threats. The research and analysis of intelligence, counter-intelligence, and open source information to identify likely adversaries to a planned operation. 3.Analysis of Vulnerabilities. Examining each aspect of the planned operation to identify OPSEC indicators that could reveal critical information and then comparing those indicators with the adversary's intelligence collection capabilities identified in the previous action. 4.Assessment of Risk. Firstly, planners analyze the vulnerabilities identified in the previous action and identify possible OPSEC measures for each vulnerability. Secondly, specific OPSEC measures are selected for execution based upon a risk assessment done by the commander and 5.Application of Appropriate OPSEC Measures. The command implements the OPSEC measures selected in the assessment of risk action or in the case of planned future operations and activities includes the measures in specific OPSEC plans. Answer option B is incorrect. Display of associated vulnerability components is not a valid step of the OPSEC process.

Topics

#OPSEC#Operations Security#Security Processes#Risk Assessment

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSMP Practice