Which Risk Management Step Establishes Scope and Identifies Potential Risks?
Which of the following steps in the risk management process involves establishing the scope and potential risks involved with a project?
Community Votes
83% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question traps candidates who conflate listing risks with analyzing them; mastering CompTIA's strict phase separation is essential for scoring high on security operations questions.
This SY0-701 question tests the precise definitions within the risk management lifecycle. Community consensus confirms that establishing project scope and cataloging potential risks belongs to risk identification, not assessment.
Candidates frequently select Risk Assessment (A) because they interpret 'identifying risks' as part of the broader evaluation process, failing to recognize that CompTIA explicitly separates initial discovery from likelihood/impact analysis.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding the Risk Management Lifecycle
CompTIA Security+ structures risk management into four distinct, sequential phases. Each phase has a specific purpose, and exam questions often test your ability to match keywords to the correct stage.
Why Risk Identification is Correct
Risk identification is the foundational step where you establish the context or scope of the project, define boundaries, and systematically catalog all potential threats, vulnerabilities, and assets. As community expert AriGarcia notes, this phase is essentially about listing possible threats before any numerical or qualitative analysis occurs. Setting the scope ensures that subsequent steps remain focused and aligned with organizational objectives.
Why Other Options Are Incorrect
Risk assessment (Option A) follows identification. It involves analyzing the identified risks to determine their likelihood, potential impact, and priority level. While some candidates argue that assessment includes identification, CompTIA strictly separates the two: identification gathers the data, and assessment evaluates it.
Risk treatment (Option C) focuses on selecting and implementing strategies to address prioritized risks, such as mitigation, avoidance, transfer, or acceptance. It does not involve scoping or initial discovery.
Risk monitoring and review (Option D) is a continuous process that tracks identified risks, measures control effectiveness, and updates the risk register as the environment changes. It occurs after treatment implementation, not at the project's outset.
Official Reference
Exam Strategy
When answering risk management questions, mentally map the four-phase cycle: Identify → Assess → Treat → Monitor. If the prompt contains words like 'scope,' 'list,' 'catalog,' or 'context,' choose Identification. If it mentions 'likelihood,' 'impact,' 'score,' or 'prioritize,' choose Assessment. This keyword mapping will help you quickly eliminate distractors.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →