nerdexam
GIAC

GSEC · Question #38

Which of the following is the FIRST step in performing an Operational Security (OP5EC) Vulnerabilities Assessment?

The correct answer is E. Identification of critical information. The OPSEC five-step process always begins with identifying critical information because every subsequent step - threat analysis, vulnerability analysis, risk assessment, and countermeasures - depends on first knowing what must be protected.

Incident Handling, Risk, and Governance

Question

Which of the following is the FIRST step in performing an Operational Security (OP5EC) Vulnerabilities Assessment?

Options

  • AAssess the threat
  • BAssess vulnerabilities of critical information to the threat
  • CConduct risk versus benefit analysis
  • DImplement appropriate countermeasures
  • EIdentification of critical information

How the community answered

(37 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    11% (4)
  • D
    3% (1)
  • E
    76% (28)

Why each option

The OPSEC five-step process always begins with identifying critical information because every subsequent step - threat analysis, vulnerability analysis, risk assessment, and countermeasures - depends on first knowing what must be protected.

AAssess the threat

Assessing the threat is the second OPSEC step and cannot be meaningfully performed until critical information has been identified in step one.

BAssess vulnerabilities of critical information to the threat

Assessing vulnerabilities of critical information is the third step and presupposes that both critical information (step 1) and threats (step 2) are already known.

CConduct risk versus benefit analysis

Risk versus benefit analysis is the fourth step and requires completed threat and vulnerability assessments from the preceding steps before it can be conducted.

DImplement appropriate countermeasures

Implementing countermeasures is the fifth and final step; applying measures before completing all prior analysis steps would be arbitrary and potentially misdirected.

EIdentification of critical informationCorrect

Identification of critical information is the mandatory first step because without knowing which information is sensitive and operationally significant, analysts have no basis to assess threats against it, identify how it could be exposed, or determine what countermeasures are warranted. The entire OPSEC process is scoped and driven by what is identified in this initial step.

Concept tested: OPSEC five-step process - first step identification

Source: https://www.cisa.gov/opsec

Topics

#OPSEC#vulnerability assessment#critical information#risk management

Community Discussion

No community discussion yet for this question.

Full GSEC Practice