CISSP · Question #1527
Drag and Drop Question What is the correct order of steps in an information security assessment? Place the information security assessment steps on the left next to the numbered boxes on the right…
The correct answer is Identify the vulnerability.; Define the perimeter.; Assess the risk.; Determine the actions. The correct order of an information security assessment follows a logical progression: first you must identify what vulnerabilities exist, then define the perimeter (scope) of what systems and assets are in scope for those vulnerabilities, next assess the risk (likelihood and…
Question
Drag and Drop Question What is the correct order of steps in an information security assessment? Place the information security assessment steps on the left next to the numbered boxes on the right in the correct order. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- Identify the vulnerability.
- Define the perimeter.
- Assess the risk.
- Determine the actions.
Explanation
The correct order of an information security assessment follows a logical progression: first you must identify what vulnerabilities exist, then define the perimeter (scope) of what systems and assets are in scope for those vulnerabilities, next assess the risk (likelihood and impact) associated with those vulnerabilities within that perimeter, and finally determine the actions (remediation, mitigation, or acceptance) to address the identified risks. This sequence ensures that scope is informed by known vulnerabilities before risk is quantified, and that decisions are made only after a full risk picture is established.
Topics
Community Discussion
No community discussion yet for this question.
