SY0-701 exam dumps

SY0-701 practice question 422 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 422

Single answerRisk identification

A company is preparing to launch a new customer portal that will process payment data and store customer records in a public cloud environment. The security analyst has been asked to perform risk identification before the system goes live. The analyst learns that the web application was developed quickly, administrators have broad access to the cloud console, and no inventory exists for third-party components used in the application. Which of the following should the analyst identify FIRST as part of the risk identification process?

  1. A

    The specific assets, threats, and vulnerabilities associated with the new portal

  2. B

    The annualized loss expectancy (ALE) for every possible attack path

  3. C

    The exact financial return on investment (ROI) for each proposed security control

  4. D

    The disciplinary actions to take if administrators violate security policy

Show answer and explanation

Correct answer: A

Explanation

The best answer is to identify the specific assets, threats, and vulnerabilities associated with the new system. In Security+ risk management, risk identification is the phase where an organization catalogs what it is trying to protect, what could negatively affect it, and where weaknesses exist. In this scenario, the portal handles regulated payment data, uses cloud administration with broad privileges, and lacks a software component inventory, all of which point to concrete risks that must be documented first. This approach aligns with common risk management practices described by NIST guidance such as NIST SP 800-30, which emphasizes identifying threat sources, vulnerabilities, likelihood, and impact as part of the risk assessment process. Only after the organization has identified relevant risks should it move into deeper qualitative or quantitative analysis, control selection, and formal risk treatment decisions.

  • A. Correct.

    Correct. Risk identification begins by determining what needs protection (assets), what could cause harm (threats), and what weaknesses could be exploited (vulnerabilities). In this scenario, examples include payment data and customer records as assets, malicious insiders or external attackers as threats, and excessive administrative privileges or unknown third-party components as vulnerabilities. This foundational step is necessary before deeper risk analysis or treatment can occur.

  • B. Incorrect.

    Incorrect. ALE is part of quantitative risk analysis, which occurs after risks have been identified. The analyst cannot calculate meaningful loss values for 'every possible attack path' until the relevant assets, threats, and vulnerabilities are first documented. A common mistake is jumping directly to financial modeling before establishing what the actual risks are.

  • C. Incorrect.

    Incorrect. ROI for security controls is part of risk response or control selection, not initial risk identification. At this stage, the organization has not yet defined the full set of risks well enough to compare control options. Candidates may choose this because cost justification is important in practice, but it is not the first step in identifying risk.

  • D. Incorrect.

    Incorrect. Disciplinary actions relate to policy enforcement and governance, not risk identification. While insider misuse may be a threat to identify, defining HR or administrative consequences does not help the analyst first determine which risks exist in the new portal environment. This distractor reflects confusion between identifying risk and responding to policy violations.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam