Akylade Certified Cyber Resilience Fundamentals ACCRF · Free Practice Question Easy
Question 14
Which of the following best describes the purpose of the Risk Assessment (ID.RA) category in the NIST Cybersecurity Framework?
- A To identify cybersecurity risks associated with that occur in operating information systems
- B To implement preventive measures against an organization's potential cybersecurity threats
- C To monitor and report on the organization's active cybersecurity threats in real time
- D To develop comprehensive cybersecurity training programs for all employees in the organization
Reveal correct answer
Correct answer: A
Explanation
The ID.RA category is designed to systematically identify risks to organizational operations, assets, individuals, and other organizations, stemming from the operation of information systems. This includes the use, processing, storage, and transmission of information. While preventive measures are important, the ID.RA category specifically focuses on assessing cybersecurity risks associated with the use, processing, storage, and transmission of information. Training programs fall under the Awareness and Training category within the Protect function, not Risk Assessment. Real-time monitoring and reporting are part of the Detect function, particularly Continuous Monitoring (DE.CM), not Risk Assessment. For support or reporting issues, include Question ID: 661c932d090aba64a3425d19 in your ticket. Thank you.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
