nerdexam
EXIN

ISFS · Question #36

You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide that it is time to draw up a risk analysis for your information system. This includes an inventory…

The correct answer is B. A risk analysis is used to clarify which threats are relevant and what risks they involve. Option B is correct because a risk analysis is a structured process that first identifies which threats are relevant to your system (not all threats apply equally to every organization), and then assesses what risks those threats pose - meaning the likelihood and potential…

Risk and security management

Question

You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide that it is time to draw up a risk analysis for your information system. This includes an inventory of the threats and risks. What is the relation between a threat, risk and risk analysis?

Options

  • AA risk analysis identifies threats from the known risks.
  • BA risk analysis is used to clarify which threats are relevant and what risks they involve.
  • CA risk analysis is used to remove the risk of a threat.
  • DRisk analyses help to find a balance between threats and risks.

How the community answered

(31 responses)
  • A
    13% (4)
  • B
    77% (24)
  • C
    6% (2)
  • D
    3% (1)

Explanation

Option B is correct because a risk analysis is a structured process that first identifies which threats are relevant to your system (not all threats apply equally to every organization), and then assesses what risks those threats pose - meaning the likelihood and potential impact of harm occurring.

A is wrong because the logic is reversed: you don't start with known risks to find threats - you start with threats to determine risks. C is wrong because a risk analysis doesn't remove risk; it only identifies and evaluates it - actual risk reduction comes from countermeasures implemented afterward. D is wrong because threats and risks aren't opposing forces to be "balanced" against each other; they exist in a cause-and-effect relationship.

Memory tip: Think of it as a chain - Threat → Risk → Analysis. A threat is the danger (e.g., a hacker), a risk is the potential damage if that threat succeeds (e.g., data breach), and a risk analysis maps out which threats are real concerns and what risks each one carries.

Topics

#risk analysis#threat identification#risk assessment#threat-risk relationship

Community Discussion

No community discussion yet for this question.

Full ISFS Practice