ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 137 - SY0-701 discussion

Report
Export

Which of the following would help ensure a security analyst is able to accurately measure the overall risk to an organization when a new vulnerability is disclosed?

A.
A full inventory of all hardware and software
Answers
A.
A full inventory of all hardware and software
B.
Documentation of system classifications
Answers
B.
Documentation of system classifications
C.
A list of system owners and their departments
Answers
C.
A list of system owners and their departments
D.
Third-party risk assessment documentation
Answers
D.
Third-party risk assessment documentation
Suggested answer: A

Explanation:

A full inventory of all hardware and software is essential for measuring the overall risk to an organization when a new vulnerability is disclosed, because it allows the security analyst to identify which systems are affected by the vulnerability and prioritize the remediation efforts. Without a full inventory, the security analyst may miss some vulnerable systems or waste time and resources on irrelevant ones.Documentation of system classifications, a list of system owners and their departments, and third-party risk assessment documentation are all useful for risk management, but they are not sufficient to measure the impact of a new vulnerability.Reference:CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, page 1221; Risk Assessment and Analysis Methods: Qualitative and Quantitative3

asked 02/10/2024
Gaston Cruz
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first