nerdexam
(ISC)2

CISSP · Question #1527

Drag and Drop Question What is the correct order of steps in an information security assessment? Place the information security assessment steps on the left next to the numbered boxes on the right…

The correct answer is Identify the vulnerability.; Define the perimeter.; Assess the risk.; Determine the actions. The correct order of an information security assessment follows a logical progression: first you must identify what vulnerabilities exist, then define the perimeter (scope) of what systems and assets are in scope for those vulnerabilities, next assess the risk (likelihood and…

Submitted by katya_ua· Mar 5, 2026Risk Management and Information Security Assessment Methodology

Question

Drag and Drop Question What is the correct order of steps in an information security assessment? Place the information security assessment steps on the left next to the numbered boxes on the right in the correct order. Answer:

Exhibit

CISSP question #1527 exhibit

Answer Area

Drag items

Define the perimeter.Identify the vulnerability.Assess the risk.Determine the actions.

Correct arrangement

  • Identify the vulnerability.
  • Define the perimeter.
  • Assess the risk.
  • Determine the actions.

Explanation

The correct order of an information security assessment follows a logical progression: first you must identify what vulnerabilities exist, then define the perimeter (scope) of what systems and assets are in scope for those vulnerabilities, next assess the risk (likelihood and impact) associated with those vulnerabilities within that perimeter, and finally determine the actions (remediation, mitigation, or acceptance) to address the identified risks. This sequence ensures that scope is informed by known vulnerabilities before risk is quantified, and that decisions are made only after a full risk picture is established.

Topics

#Information Security Assessment#Risk Management#Vulnerability Assessment#Security Governance

Community Discussion

No community discussion yet for this question.

Full CISSP Practice