ITPEC IP October 2019 Question 37
ITPEC IP October 2019 — Question 37 of 100
Risk assessment identifies and analyzes risks to information assets, evaluates them against criteria, and determines whether treatment is necessary. It considers factors such as asset value, threats, vulnerabilities, likelihood, and impact to prioritize action.
Answer (b)
Why not others:
- quarantining malware is incident response or risk treatment
- verifying a user's identity is authentication
- calculating the cost effectiveness of a system is an investment evaluation rather than an information-security risk assessment
Key rule: Assessment measures and evaluates risk; treatment then avoids, reduces, transfers, or accepts that assessed risk.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.