nerdexam
(ISC)2

SSCP · Question #1227

Which of the following steps are involved in a basic risk assessment?

The correct answer is E. All of the items listed. A basic risk assessment encompasses identifying assets, evaluating threats, considering legal/financial/regulatory impacts, and determining the likelihood of adverse events.

Submitted by ngozi_ng· Apr 18, 2026Risk Identification, Monitoring and Analysis

Question

Which of the following steps are involved in a basic risk assessment?

Options

  • ADetermine what data and systems need to be protected
  • BEvaluate who are the potential threats
  • CInvestigate potential legal, financial, and regulatory issues
  • DDetermine the chances of a disaster or risk related event occurring
  • EAll of the items listed
  • FNone of the items listed

How the community answered

(60 responses)
  • A
    3% (2)
  • B
    2% (1)
  • D
    2% (1)
  • E
    93% (56)

Why each option

A basic risk assessment encompasses identifying assets, evaluating threats, considering legal/financial/regulatory impacts, and determining the likelihood of adverse events.

ADetermine what data and systems need to be protected
BEvaluate who are the potential threats
CInvestigate potential legal, financial, and regulatory issues
DDetermine the chances of a disaster or risk related event occurring
EAll of the items listedCorrect

E is correct because all the listed options-determining what data and systems to protect, evaluating potential threats, investigating legal/financial/regulatory issues, and assessing the likelihood of events-are fundamental and integral components of a comprehensive risk assessment process. These steps collectively help an organization understand its risk posture and prioritize mitigation strategies.

FNone of the items listed

Concept tested: Risk assessment components

Source: https://learn.microsoft.com/en-us/compliance/regulatory/risk-assessment-approach

Topics

#Risk assessment#Risk management process#Threat identification#Asset identification

Community Discussion

No community discussion yet for this question.

Full SSCP Practice