ISFS · Question #53
What is the best description of a risk analysis?
The correct answer is B. A risk analysis helps to estimate the risks and develop the appropriate security measures. Option B is correct because risk analysis is fundamentally about identifying, estimating, and prioritizing risks so that appropriate security controls or mitigations can be designed and implemented - it is an evaluative process, not just a mapping exercise. Why A is wrong: Risk…
Question
What is the best description of a risk analysis?
Options
- AA risk analysis is a method of mapping risks without looking at company processes.
- BA risk analysis helps to estimate the risks and develop the appropriate security measures.
- CA risk analysis calculates the exact financial consequences of damages.
How the community answered
(24 responses)- A8% (2)
- B83% (20)
- C8% (2)
Explanation
Option B is correct because risk analysis is fundamentally about identifying, estimating, and prioritizing risks so that appropriate security controls or mitigations can be designed and implemented - it is an evaluative process, not just a mapping exercise.
Why A is wrong: Risk analysis absolutely must consider company processes - you cannot assess risk in a vacuum. Ignoring processes would make any analysis meaningless, since threats and vulnerabilities are typically tied to how an organization operates.
Why C is wrong: Risk analysis does not calculate exact financial figures. It produces estimates (often ranges or likelihood × impact scores). Precise financial calculation is more characteristic of quantitative risk assessment in specific contexts, but even then "exact" is too strong a claim.
Memory tip: Think of risk analysis as the "estimate and respond" phase - you're sizing up threats and deciding what to do about them. If an answer says risks are mapped without context (A) or implies perfect precision (C), it's describing something else entirely.
Topics
Community Discussion
No community discussion yet for this question.