Courseiva
mediumDrag & DropObjective-mapped

CISSP Practice Question: Drag and drop the steps for conducting a risk…

Drag and drop the steps for conducting a risk assessment in the correct order.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Step 1: Identify assets Step 2: Identify threats and vulnerabilities Step 3: Determine likelihood and impact Step 4: Calculate risk Step 5: Recommend treatments

Risk assessment begins with asset identification, then threat/vulnerability identification, likelihood/impact determination, risk calculation, and treatment recommendations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Step 1: Identify assets Step 2: Identify threats and vulnerabilities Step 3: Determine likelihood and impact Step 4: Calculate risk Step 5: Recommend treatments

    Why this is correct

    This is the correct order because risk assessment must first identify what assets are at risk, then determine what threats and vulnerabilities exist, assess their likelihood and impact, calculate the overall risk level, and finally recommend appropriate treatments to mitigate the risk.

  • Step 1: Identify threats and vulnerabilities Step 2: Identify assets Step 3: Determine likelihood and impact Step 4: Calculate risk Step 5: Recommend treatments

    Why it's wrong here

    This sequence is fundamentally flawed because identifying threats and vulnerabilities in a vacuum, without first defining the assets to be protected, is an abstract and inefficient exercise. A risk assessment must begin by establishing the scope of what needs protection—the assets—before meaningful threats (e.g., unauthorized access to specific data) and vulnerabilities (e.g., unpatched software on a critical server) can be identified in relation to those assets. Without clearly defined assets, there is no practical context for risk identification.

  • Step 1: Identify assets Step 2: Determine likelihood and impact Step 3: Identify threats and vulnerabilities Step 4: Calculate risk Step 5: Recommend treatments

    Why it's wrong here

    This order incorrectly attempts to determine likelihood and impact before identifying the specific threats and vulnerabilities that could affect the assets. Likelihood and impact are attributes directly associated with a risk event, which is the realization of a threat exploiting a vulnerability against an asset. One cannot accurately assess the probability of an event occurring or its potential consequences without first clearly defining what that specific event entails, making this step premature.

  • Step 1: Calculate risk Step 2: Identify assets Step 3: Identify threats and vulnerabilities Step 4: Determine likelihood and impact Step 5: Recommend treatments

    Why it's wrong here

    Initiating a risk assessment by attempting to calculate risk is illogical, as risk is a derived value resulting from the analysis of multiple preceding factors. Risk calculation typically involves combining the assessed likelihood of a threat exploiting a vulnerability and the potential impact on an asset. Without first identifying the assets, their associated threats and vulnerabilities, and then evaluating their respective likelihoods and impacts, there are no inputs available to perform a meaningful risk calculation.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.