nerdexam
(ISC)2

CSSLP · Question #273

Which of the following steps of the LeGrand Vulnerability-Oriented Risk Management method determines the necessary compliance offered by risk management practices and assessment of risk levels?

The correct answer is A. Assessment, monitoring, and assurance. In the LeGrand Vulnerability-Oriented Risk Management method, the 'Assessment, monitoring, and assurance' step is responsible for evaluating the compliance of risk management practices and continuously assessing current risk levels to ensure ongoing security.

Secure Software Concepts

Question

Which of the following steps of the LeGrand Vulnerability-Oriented Risk Management method determines the necessary compliance offered by risk management practices and assessment of risk levels?

Options

  • AAssessment, monitoring, and assurance
  • BVulnerability management
  • CRisk assessment
  • DAdherence to security standards and policies for development and deployment

How the community answered

(50 responses)
  • A
    92% (46)
  • B
    2% (1)
  • C
    4% (2)
  • D
    2% (1)

Why each option

In the LeGrand Vulnerability-Oriented Risk Management method, the 'Assessment, monitoring, and assurance' step is responsible for evaluating the compliance of risk management practices and continuously assessing current risk levels to ensure ongoing security.

AAssessment, monitoring, and assuranceCorrect

The 'Assessment, monitoring, and assurance' step in the LeGrand method explicitly covers the ongoing evaluation of risk management practices, ensuring compliance, and continuously assessing and assuring the appropriate level of risk and control effectiveness.

BVulnerability management

Vulnerability management focuses specifically on identifying, prioritizing, and remediating vulnerabilities, which is a sub-component of risk management, but not the overall determination of compliance and assurance.

CRisk assessment

Risk assessment is the process of identifying and analyzing risks, which is part of determining risk levels, but does not encompass the broader compliance and ongoing assurance aspects mentioned in the question.

DAdherence to security standards and policies for development and deployment

Adherence to security standards and policies is an objective or a desired state to be achieved, rather than a step that performs the actual determination of compliance and assessment of risk levels itself.

Concept tested: LeGrand Vulnerability-Oriented Risk Management steps

Topics

#Risk Management Methodologies#LeGrand Method#Compliance Assurance#Vulnerability Management

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice