Certified In Cybersecurity CC · Free Practice Question Easy
Question 25
Risk Management is:
-
A
The creation of an incident response team
-
B
The identification, evaluation and prioritization of risks
-
C
The impact and likelihood of a threat
-
D
The assessment of the potential impact of a threat
Reveal correct answer
Correct answer: B
Explanation
Risk management in cybersecurity involves identifying potential risks, evaluating their severity, and prioritizing actions based on the level of threat they pose (see ISC2 Study Guide, Domain 1).
As an example of risk management, an organization might identify a risk of data theft (identification), assess how likely and damaging a breach could be (evaluation), and prioritize stronger encryption practices to mitigate that risk (prioritization).
The other answers do not fully capture the essence of risk management. The assessment of the potential impact of a threat is just one part of the risk evaluation process, not the entirety of risk management. The impact and likelihood of a threat are components of the evaluation phase in risk management. Finally, creating an incident response team is a response strategy, not a risk management process.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
