nerdexam
(ISC)2

CISSP · Question #566

Which of the following needs to be taken into account when assessing vulnerability?

The correct answer is A. Risk identification and validation. Vulnerability assessment requires identifying and validating risks to understand what weaknesses exist and whether they are genuine threats to the environment.

Submitted by andreas_gr· Mar 5, 2026Security Assessment and Testing

Question

Which of the following needs to be taken into account when assessing vulnerability?

Options

  • ARisk identification and validation
  • BThreat mapping
  • CRisk acceptance criteria
  • DSafeguard selection

How the community answered

(25 responses)
  • A
    92% (23)
  • C
    4% (1)
  • D
    4% (1)

Why each option

Vulnerability assessment requires identifying and validating risks to understand what weaknesses exist and whether they are genuine threats to the environment.

ARisk identification and validationCorrect

Risk identification and validation are core components of vulnerability assessment because the process involves discovering potential weaknesses (identification) and confirming they are real, exploitable vulnerabilities rather than false positives (validation). Without both steps, an organization cannot accurately understand its exposure or prioritize remediation efforts.

BThreat mapping

Threat mapping is an activity associated with threat modeling and threat intelligence analysis, not a primary consideration within vulnerability assessment itself.

CRisk acceptance criteria

Risk acceptance criteria is part of the risk management and risk treatment decision-making process that occurs after vulnerabilities have already been assessed, not during the assessment phase.

DSafeguard selection

Safeguard selection is a risk response and mitigation activity that takes place after vulnerabilities have been identified and evaluated, making it a subsequent step rather than a consideration during assessment.

Concept tested: Core components of vulnerability assessment process

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#Vulnerability assessment#Risk identification#Risk management

Community Discussion

No community discussion yet for this question.

Full CISSP Practice