Q: 14
The first task of a security practitioner in a security risk assessment is to develop an understanding of
the:
Options
Discussion
Option B that's what I've seen referenced in official guides and practice tests. Always start with understanding the organization.
I don’t think it’s A, the trap here is going straight for vulnerabilities. Similar exam questions always expect B first, gotta know the organization before you can assess anything else.
B , that matches what every framework says. Gotta know the org inside out before you can size up risks or anything else. Seen this as the first step in most CPP prep.
Probably B , had something like this in a mock. Order always starts with understanding the organization.
Be respectful. No spam.