mediumMultiple SelectObjective-mapped
CAS-004 Practice Question: Which TWO of the following are key components of…
Which TWO of the following are key components of a risk assessment methodology?
⚠ Common exam trap
CompTIA CASP+ often tests the distinction between proactive risk assessment components (threat identification, asset inventory) and reactive operational processes (disaster recovery, incident response), expecting candidates to recognize that risk appetite is a governance policy input, not a step in the methodology.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat identification.
Threat identification (B) is a core component of a risk assessment methodology because it systematically catalogs potential sources of harm that could exploit vulnerabilities in the environment. Without identifying threats—such as malware, insider threats, or natural disasters—the subsequent risk analysis cannot calculate likelihood or impact. Asset inventory (E) is equally fundamental because risk is always assessed in the context of what is valuable or critical to the organization; you cannot evaluate risk to assets you do not know exist.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disaster recovery.
Why it's wrong here
Disaster recovery is a plan for after incidents, not part of risk assessment.
- ✓
Threat identification.
Why this is correct
Identifying threats is a fundamental step in risk assessment.
- ✗
Risk appetite.
Why it's wrong here
Risk appetite defines the level of risk the organization is willing to accept; it is a policy input, not a methodology step.
- ✗
Incident response.
Why it's wrong here
Incident response is a separate process, not part of risk assessment methodology.
- ✓
Asset inventory.
Why this is correct
Knowing what assets are valuable and vulnerable is essential.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.