Certified In Cybersecurity CC · Free Practice Question Easy

Question 25

Risk Management is:

  • A

    The creation of an incident response team

  • B

    The identification, evaluation and prioritization of risks

  • C

    The impact and likelihood of a threat

  • D

    The assessment of the potential impact of a threat

Reveal correct answer

Correct answer: B

Explanation

Risk management in cybersecurity involves identifying potential risks, evaluating their severity, and prioritizing actions based on the level of threat they pose (see ISC2 Study Guide, Domain 1).

As an example of risk management, an organization might identify a risk of data theft (identification), assess how likely and damaging a breach could be (evaluation), and prioritize stronger encryption practices to mitigate that risk (prioritization).

The other answers do not fully capture the essence of risk management. The assessment of the potential impact of a threat is just one part of the risk evaluation process, not the entirety of risk management. The impact and likelihood of a threat are components of the evaluation phase in risk management. Finally, creating an incident response team is a response strategy, not a risk management process.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need