Application Risk Assessment Questions
The application development teams have been asked to answer the following questions: • Does this application receive patches from an external source? • Does this application contain open-source code? • Is this application accessible by external users? • Does this application meet the corporate password standard? Which of the following are these questions part of?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the ability to distinguish between proactive self-assessment questionnaires and static risk documentation tools like matrices.
Identifies the specific risk management process used to evaluate application security and compliance through targeted internal questions.
Confusing the assessment activity with a risk matrix, which is a tool for scoring rather than a process for gathering data.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct answer is A. These questions are part of a Risk Control Self-Assessment (RCSA). An RCSA is an internal process where stakeholders identify risks and assess the effectiveness of controls in place. The questions listed—regarding external patches, open-source code, external accessibility, and password standards—are typical control checks performed during such an assessment to determine if the application meets organizational risk appetite and compliance requirements.Why the Other Options Are Wrong
B is incorrect because a Risk Management Strategy is a high-level framework or plan, not a set of operational questions. C is incorrect because Risk Acceptance is the final decision to tolerate a risk after it has been assessed, not the assessment process itself. D is incorrect because a Risk Matrix is a visual tool used to plot the probability and impact of risks; it does not generate the questions used to gather the underlying data.Community Comment Notes
Community consensus strongly supports option A. As user Jay987654 noted, "These questions are part of an A. Risk Control Self-Assessment... aimed at understanding the potential risks associated with the application." Another commenter emphasized that RCSAs are "often performed through questionnaires," which aligns perfectly with the format of the questions provided in the scenario.Exam Strategy
When you see a list of specific questions asked to business units or development teams about their controls, think 'Self-Assessment' or 'Questionnaire'. If the question asks about plotting likelihood vs impact, think 'Matrix'. If it asks about the overall approach, think 'Strategy'.
Frequently Asked Questions
How does RCSA differ from a Risk Matrix?
RCSA is the process of gathering data via questionnaires to identify risks. A Risk Matrix is a tool used later to visualize and score those risks based on probability and impact.
Are these questions part of a security audit?
While similar, RCSA is typically self-initiated by the team or department for internal governance, whereas an audit is often independent and retrospective.