CISSP · Question #566
Which of the following needs to be taken into account when assessing vulnerability?
The correct answer is A. Risk identification and validation. Vulnerability assessment requires identifying and validating risks to understand what weaknesses exist and whether they are genuine threats to the environment.
Question
Which of the following needs to be taken into account when assessing vulnerability?
Options
- ARisk identification and validation
- BThreat mapping
- CRisk acceptance criteria
- DSafeguard selection
How the community answered
(25 responses)- A92% (23)
- C4% (1)
- D4% (1)
Why each option
Vulnerability assessment requires identifying and validating risks to understand what weaknesses exist and whether they are genuine threats to the environment.
Risk identification and validation are core components of vulnerability assessment because the process involves discovering potential weaknesses (identification) and confirming they are real, exploitable vulnerabilities rather than false positives (validation). Without both steps, an organization cannot accurately understand its exposure or prioritize remediation efforts.
Threat mapping is an activity associated with threat modeling and threat intelligence analysis, not a primary consideration within vulnerability assessment itself.
Risk acceptance criteria is part of the risk management and risk treatment decision-making process that occurs after vulnerabilities have already been assessed, not during the assessment phase.
Safeguard selection is a risk response and mitigation activity that takes place after vulnerabilities have been identified and evaluated, making it a subsequent step rather than a consideration during assessment.
Concept tested: Core components of vulnerability assessment process
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.