Which of the following would help ensure a security analyst is able to accurately measure the overall risk to an organization when a new vulnerability is disclosed?
Choose an answer
Tap an option to check your answer.
Correct answer: A full inventory of all hardware and software.
Why this is the answer
A full inventory of all hardware and software (asset inventory) is crucial because it allows a security analyst to identify which systems are affected by a newly disclosed vulnerability. Without knowing what assets exist, it's impossible to determine the scope of the vulnerability or the potential impact, thus preventing an accurate risk assessment. Documentation of system classifications is helpful for understanding the criticality of systems, but without an inventory, you don't know which systems those classifications apply to. A list of system owners is important for communication and accountability but doesn't directly help in identifying vulnerable assets. Third-party risk assessment documentation focuses on external risks, not the internal impact of a new vulnerability on an organization's own assets.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed