ISFS · Question #1
What is a risk analysis used for?
The correct answer is D. A risk analysis is used to ensure that security measures are deployed in a cost-effective and timely fashion. Risk analysis is fundamentally a decision-support tool that ensures security controls are implemented where they provide the most value relative to cost and are put in place before threats materialize - making D correct. Option A describes asset valuation, a component that…
Question
What is a risk analysis used for?
Options
- AA risk analysis is used to express the value of information for an organization in monetary terms.
- BA risk analysis is used to clarify to management their responsibilities.
- CA risk analysis is used in conjunction with security measures to reduce risks to an acceptable level.
- DA risk analysis is used to ensure that security measures are deployed in a cost-effective and timely fashion.
How the community answered
(47 responses)- A15% (7)
- B6% (3)
- C4% (2)
- D74% (35)
Explanation
Risk analysis is fundamentally a decision-support tool that ensures security controls are implemented where they provide the most value relative to cost and are put in place before threats materialize - making D correct. Option A describes asset valuation, a component that feeds into a risk analysis but is not its purpose. Option B describes a function of a security policy or governance framework, not risk analysis itself. Option C is close but misleading - risk analysis identifies and quantifies risks; it's the security measures that reduce them, not the analysis itself.
Memory tip: Think of risk analysis as a "shopping guide" for security - it tells you what to buy, how much to spend, and when to buy it so you don't overspend on the wrong items too late.
Topics
Community Discussion
No community discussion yet for this question.