Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementEasy

A cybersecurity analyst is evaluating a new cloud-based application that stores sensitive customer data. The analyst identifies that the application uses a third-party authentication service. What is the primary risk management concept being applied when considering the potential vulnerabilities introduced by this third-party service?

  1. ARisk Identification
  2. BRisk Transfer
  3. CRisk Mitigation
  4. DRisk Acceptance
Show answer & explanation

Correct answer: A. Risk Identification

Before any other risk management activities can occur, potential threats and vulnerabilities must be identified. Recognizing the third-party service as a potential source of vulnerability falls under risk identification.

Why the other options are wrong

  • B. Risk transfer involves shifting the risk to another party, typically through insurance or contractual agreements, which is a mitigation strategy.
  • C. Risk mitigation involves taking steps to reduce the likelihood or impact of a risk, which happens after identification and assessment.
  • D. Risk acceptance is a decision made after risks have been identified and assessed.

Risk Identification

The process of discovering, recognizing, and describing risks that could affect an organization's assets.

  • First step in risk management.
  • Involves identifying threats, vulnerabilities, and assets.
  • Can be qualitative or quantitative.

Memory trick: Identify, Analyze, Respond, Monitor: The four pillars of risk control.

More Risk Management questions