nerdexam
CompTIA

CS0-003 · Question #109

A company has alerted planning the implemented a vulnerability management procedure. However, to security maturity level is low, so there are some prerequisites to complete before risk calculation…

The correct answer is D. A risk identification process. For a company with low security maturity, the first prerequisite for a vulnerability management procedure, before risk calculation and prioritization, is to identify what the risks are.

Submitted by kev92· Mar 6, 2026Vulnerability Management

Question

A company has alerted planning the implemented a vulnerability management procedure. However, to security maturity level is low, so there are some prerequisites to complete before risk calculation and prioritization. Which of the following should be completed FIRST?

Options

  • AA business Impact analysis
  • BA system assessment
  • CCommunication of the risk factors
  • DA risk identification process

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    12% (3)
  • D
    80% (20)

Why each option

For a company with low security maturity, the first prerequisite for a vulnerability management procedure, before risk calculation and prioritization, is to identify what the risks are.

AA business Impact analysis

A business impact analysis (BIA) helps determine the potential effects of an incident, which contributes to risk impact, but it logically follows or runs concurrently with initial risk identification.

BA system assessment

A system assessment helps identify vulnerabilities, which are components of risk, but the broader risk identification process encompasses threats, assets, and the overall context before technical assessments.

CCommunication of the risk factors

Communication of risk factors is an outcome of the risk management process, occurring after risks have been identified, analyzed, and prioritized.

DA risk identification processCorrect

Before risk calculation and prioritization can occur, a company must first undertake a risk identification process to discover and document potential threats and vulnerabilities to its assets. Without clearly identified risks, it is impossible to accurately assess their impact or likelihood, or to prioritize them effectively.

Concept tested: Risk management framework - Risk identification

Source: https://csrc.nist.gov/publications/detail/sp/800-39/final

Topics

#Vulnerability management program#Risk identification#Security maturity#Program development

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice