An organization’s process of identifying and assessing risk with the goal of reducing these threats to an acceptable level is known as what?
- Business continuity
- Disaster recovery
- Risk management
- Vulnerability scanning
Explanation: Risk management is the formal and continuous process of identifying and assessing risks to an organization. Its primary goal is to reduce the impact of threats and vulnerabilities to an acceptable level by weighing the impact of a threat against the cost of implementing security controls.
Related exam: Introduction to Cybersecurity final course exam answers
