EX0-111 · Question #49
Which of the following is a method for managing risk?
The correct answer is C. CRAMM. CRAMM (CCTA Risk Analysis and Management Method) is a real, established risk management framework originally developed by the UK government's Central Computer and Telecommunications Agency (CCTA) for analyzing and managing information security risks. It provides a structured…
Question
Which of the following is a method for managing risk?
Options
- APRAMM.
- BTRAMM.
- CCRAMM.
- DGRAMM.
How the community answered
(25 responses)- A4% (1)
- C92% (23)
- D4% (1)
Explanation
CRAMM (CCTA Risk Analysis and Management Method) is a real, established risk management framework originally developed by the UK government's Central Computer and Telecommunications Agency (CCTA) for analyzing and managing information security risks. It provides a structured, three-stage process covering asset identification, threat/vulnerability assessment, and countermeasure selection.
Options A (PRAMM), B (TRAMM), and D (GRAMM) are fabricated acronyms designed to test whether you know the real methodology - none of them correspond to recognized risk management frameworks.
Memory tip: Think of the C in CRAMM as standing for "Correct" or associate it with CCTA (the agency that created it) - both the method and its creator start with C. If you see a risk management acronym on the exam ending in -RAMM, the real one starts with C.
Topics
Community Discussion
No community discussion yet for this question.