mediumMultiple Select
CAS-004 Practice Question: Which TWO of the following are key components of…
Which TWO of the following are key components of a risk assessment methodology?
⚠ Common exam trap
CompTIA CASP+ often tests the distinction between proactive risk assessment components (threat identification, asset inventory) and reactive operational processes (disaster recovery, incident response), expecting candidates to recognize that risk appetite is a governance policy input, not a step in the methodology.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat identification.
Threat identification (B) is a core component of risk assessment because risk is derived from threats acting on vulnerabilities, so the methodology must enumerate and characterize relevant threat sources (e.g., natural, human, environmental) before likelihood and impact can be estimated. Asset inventory (E) is equally essential, since risk assessment requires knowing which assets (hardware, software, data, personnel, facilities) have value and therefore what could be harmed, enabling proper scoping and impact analysis. Together, asset inventory and threat identification feed the standard risk calculation (Risk = Threat × Vulnerability × Impact) used in frameworks such as NIST SP 800-30 and ISO/IEC 27005. Disaster recovery (A) is a reactive continuity capability, not a risk assessment input, and it is addressed after risks are evaluated. Risk appetite (C) is a governance decision about acceptable risk levels that guides treatment, not a component of the assessment itself. Incident response (D) is an operational capability for detecting and handling security events, which likewise falls outside the assessment methodology.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disaster recovery.
Why it's wrong here
Disaster recovery restores IT services after disruption, operating post-event rather than assessing risk beforehand. It tempts because it belongs to the broader risk management programme, but the assessment methodology itself covers asset identification, threat and vulnerability analysis, and risk evaluation.
- ✓
Threat identification.
Why this is correct
Threat identification enumerates the threat sources and events capable of exploiting vulnerabilities, forming the basis for estimating likelihood. It satisfies the methodology's requirement to establish what could cause harm before assessing impact and risk levels.
- ✗
Risk appetite.
Why it's wrong here
Risk appetite is the tolerance threshold an organisation sets for accepting risk; it guides decisions but is not a component of the assessment methodology itself. It tempts because appetite shapes how findings are judged, yet the methodology comprises identification, analysis, evaluation and treatment processes.
- ✗
Incident response.
Why it's wrong here
Incident response handles security events after they occur, whereas risk assessment estimates likelihood and impact beforehand. It tempts because both sit within risk management, but response is a reactive capability, not a component of the assessment methodology's identification and analysis steps.
- ✓
Asset inventory.
Why this is correct
An asset inventory catalogues the systems, data, and resources requiring protection, establishing scope and value for the assessment. It satisfies the methodology's requirement to know what is being risk-assessed before threats and vulnerabilities can be mapped against it.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.