Certified In Cybersecurity CC · Free Practice Question Easy

Question 35

Which of the following statements is the PRIMARY indicator that risk assessment is an iterative process?
  • A The risk assessment process is based on the organization's overall risk tolerance
  • B The risk assessment process is dependent on the level of security controls in place
  • C The risk assessment process is repeated on a regular basis
  • D The risk assessment process considers new information and changes to the organization's environment
Reveal correct answer

Correct answer: C

Explanation

The correct answer: The risk assessment process is repeated on a regular basis: Risk assessment is an iterative process because it needs to be repeated over time. The purpose of this is to identify new risks, reassess existing risks, and to check if the risk mitigation measures implemented are working effectively. This is due to the fact that the risk landscape of an organization is never static; it changes with time due to several factors such as changes in the business environment, regulatory changes, new threats, changes in the organization's operations, and so on. Conducting risk assessments regularly is the primary indicator of it being an iterative process. The incorrect answers: The risk assessment process is dependent on the level of security controls in place: While the level of security controls in place can affect the results of a risk assessment (i.e., more controls might reduce risk), it is not the primary indicator that risk assessment is an iterative process. Risk assessments are repeated over time regardless of the number or effectiveness of security controls. This answer confuses the influence that security controls have on the outcome of risk assessments with the process of risk assessment itself. The risk assessment process is based on the organization's overall risk tolerance: Risk tolerance, or the amount of risk an organization is willing to accept, can certainly guide the process and outcomes of risk assessments. It does not indicate that risk assessment is an iterative process. Risk tolerance helps to determine how risks identified during the risk assessment process are addressed (mitigated, accepted, transferred, or avoided), but it does not necessitate the repetition of risk assessments over time. The risk assessment process considers new information and changes to the organization's environment: While this statement is accurate and reflects the need for risk assessments to be updated as circumstances change, it is not the primary indicator that risk assessment is an iterative process. This is more of a reason why risk assessment should be iterative, rather than an indicator that it is. Considering new information and changes in the environment is a part of the single iteration of risk assessment. The fact that these assessments are performed repeatedly over time is what makes the process iterative.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need