A company is performing a risk assessment on new software the company plans to use. Which of the following should the company assess during this process?
Choose an answer
Tap an option to check your answer.
Correct answer: Software vulnerabilities.
Why this is the answer
During a risk assessment for new software, evaluating software vulnerabilities is crucial. This directly identifies potential weaknesses that attackers could exploit, leading to data breaches, system compromise, or service disruption. Understanding these vulnerabilities allows the company to implement appropriate controls or decide against using the software if risks are too high. While a cost-benefit analysis is important for overall project approval, it's a financial assessment, not a direct risk assessment of the software itself. Ongoing monitoring strategies are for post-deployment risk management, not the initial assessment phase. Network infrastructure compatibility ensures the software functions, but doesn't directly assess the security risks inherent in the software's code or design.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed