nerdexam
(ISC)2

CISSP · Question #1159

When designing a Cyber-Physical System (CPS), which of the following should be a security practitioner's first consideration?

The correct answer is D. Risk assessment of the system. A risk assessment is the first step in designing a secure CPS, as it helps to identify the threats, vulnerabilities, impacts, and likelihoods of the system. A risk assessment also helps to prioritize the security requirements and controls for the system, based on the risk appetit

Submitted by paula_co· Mar 5, 2026Security and Risk Management

Question

When designing a Cyber-Physical System (CPS), which of the following should be a security practitioner's first consideration?

Options

  • ADetection of sophisticated attackers
  • BResiliency of the system
  • CTopology of the network used for the system
  • DRisk assessment of the system

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    17% (4)
  • D
    71% (17)

Explanation

A risk assessment is the first step in designing a secure CPS, as it helps to identify the threats, vulnerabilities, impacts, and likelihoods of the system. A risk assessment also helps to prioritize the security requirements and controls for the system, based on the risk appetite and tolerance of the organization. Detection, resiliency, and topology are important aspects of CPS security, but they depend on the outcome of the risk assessment.

Topics

#Cyber-Physical Systems#risk assessment#security design principles

Community Discussion

No community discussion yet for this question.

Full CISSP Practice