Drag steps to the numbered slots on the right, or tap a step then tap a slot.
CISSP Practice Question: Drag and drop the steps for conducting a risk…
Drag and drop the steps for conducting a risk assessment in the correct order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Step 1: Identify assets Step 2: Identify threats and vulnerabilities Step 3: Determine likelihood and impact Step 4: Calculate risk Step 5: Recommend treatments
Risk assessment begins with asset identification, then threat/vulnerability identification, likelihood/impact determination, risk calculation, and treatment recommendations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Step 1: Identify assets Step 2: Identify threats and vulnerabilities Step 3: Determine likelihood and impact Step 4: Calculate risk Step 5: Recommend treatments
Why this is correct
This is the correct order because risk assessment must first identify what assets are at risk, then determine what threats and vulnerabilities exist, assess their likelihood and impact, calculate the overall risk level, and finally recommend appropriate treatments to mitigate the risk.
- ✗
Step 1: Identify threats and vulnerabilities Step 2: Identify assets Step 3: Determine likelihood and impact Step 4: Calculate risk Step 5: Recommend treatments
Why it's wrong here
This sequence is fundamentally flawed because identifying threats and vulnerabilities in a vacuum, without first defining the assets to be protected, is an abstract and inefficient exercise. A risk assessment must begin by establishing the scope of what needs protection—the assets—before meaningful threats (e.g., unauthorized access to specific data) and vulnerabilities (e.g., unpatched software on a critical server) can be identified in relation to those assets. Without clearly defined assets, there is no practical context for risk identification.
- ✗
Step 1: Identify assets Step 2: Determine likelihood and impact Step 3: Identify threats and vulnerabilities Step 4: Calculate risk Step 5: Recommend treatments
Why it's wrong here
This order incorrectly attempts to determine likelihood and impact before identifying the specific threats and vulnerabilities that could affect the assets. Likelihood and impact are attributes directly associated with a risk event, which is the realization of a threat exploiting a vulnerability against an asset. One cannot accurately assess the probability of an event occurring or its potential consequences without first clearly defining what that specific event entails, making this step premature.
- ✗
Step 1: Calculate risk Step 2: Identify assets Step 3: Identify threats and vulnerabilities Step 4: Determine likelihood and impact Step 5: Recommend treatments
Why it's wrong here
Initiating a risk assessment by attempting to calculate risk is illogical, as risk is a derived value resulting from the analysis of multiple preceding factors. Risk calculation typically involves combining the assessed likelihood of a threat exploiting a vulnerability and the potential impact on an asset. Without first identifying the assets, their associated threats and vulnerabilities, and then evaluating their respective likelihoods and impacts, there are no inputs available to perform a meaningful risk calculation.
Go deeper
Related to this question
Learn chapter
Asset Security: Classification and Handling
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Risk assessment
Risk assessment is the process of identifying, analyzing, and evaluating potential threats to an organization's assets to determine the likelihood and impact of those threats, and to decide on appropriate treatment measures.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.