Certified In Cybersecurity CC · Free Practice Question Easy
Question 54
As the lead security consultant for a large corporation, you are working with the HR department to educate employees on cybersecurity best practices. Which of the following is least relevant in managing cyber security risks?
- A Identifying and prioritizing assets
- B Implementing security measures to prevent threats
- C Evaluating and mitigating vulnerabilities
- D Performing regular software updates
Reveal correct answer
Correct answer: A
Explanation
The correct answer: Identifying and prioritizing assets: While identifying and prioritizing assets is indeed a critical part of an overall risk management strategy, it is not directly involved in managing cyber security risks. When dealing with cyber security risks specifically, we focus on actions that directly address the threats and vulnerabilities that exist in the digital realm. Hence, it could be considered the least relevant among the options provided, even though it is still an important step in the broader context of information security. The incorrect answers: Evaluating and mitigating vulnerabilities: Evaluating and mitigating vulnerabilities is a crucial part of managing cyber security risks. Vulnerabilities can be exploited by threat actors to gain unauthorized access to systems or data, so identifying and addressing these vulnerabilities can significantly reduce cyber security risks. Performing regular software updates: Regular software updates often contain patches for known security vulnerabilities, making this an important part of managing cyber security risks. Out-of-date software can leave systems susceptible to attacks that exploit known vulnerabilities. Implementing security measures to prevent threats: Implementing security measures to prevent threats is a key part of managing cyber security risks. This could include measures such as deploying firewalls, implementing access controls, and setting up intrusion detection and prevention systems. These measures help to deter or prevent threat actors from compromising systems and data.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
