QuestionQ11

Cybersecurity Principles and Risks

Which of the following would BEST enable an organization to prioritize remediation actions when multiple vulnerabilities have been identified?

  • A Risk assessment
  • B Business impact analysis (BIA)
  • C Vulnerability exception process
  • D Executive reporting process
Explanation

A risk assessment ranks vulnerabilities according to their likelihood of exploitation and potential organizational impact, allowing remediation resources to be directed first to the highest-risk issues.

Community Discussion

No comments yet. Be the first to start the discussion!