Which Risk Management Step Establishes Scope and Identifies Potential Risks?

Which of the following steps in the risk management process involves establishing the scope and potential risks involved with a project?

  1. Risk assessment
  2. Risk identification Source Reference Answer
  3. Risk treatment
  4. Risk monitoring and review

Community Votes

B
83%
A
17%

83% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question traps candidates who conflate listing risks with analyzing them; mastering CompTIA's strict phase separation is essential for scoring high on security operations questions.

This SY0-701 question tests the precise definitions within the risk management lifecycle. Community consensus confirms that establishing project scope and cataloging potential risks belongs to risk identification, not assessment.

Candidates frequently select Risk Assessment (A) because they interpret 'identifying risks' as part of the broader evaluation process, failing to recognize that CompTIA explicitly separates initial discovery from likelihood/impact analysis.

Community Discussion (6 comments)

AriGarcia 👍 5 Selected: B
While both are part of risk management, "risk identification" is the initial step of recognizing and listing potential risks, while "risk assessment" involves analyzing and evaluating those identified risks to determine their likelihood and potential impact, essentially prioritizing them for mitigation strategies; in simpler terms, risk identification is just listing possible threats, while risk assessment is figuring out how serious each threat could be
Anyio 👍 2 Selected: B
Answer: B. Risk identification Risk identification is the step in the risk management process where the scope of the project is established, and potential risks are identified. This step lays the groundwork for understanding what risks could impact the project. Why the other options are not correct: A. Risk assessment Risk assessment involves analyzing and evaluating the identified risks to determine their likelihood and impact. It occurs after risk identification, so it doesn't involve establishing the scope or identifying potential risks initially. C. Risk treatment Risk treatment focuses on developing and implementing strategies to mitigate, avoid, transfer, or accept risks. This step occurs after risks have been identified and assessed, so it doesn't involve establishing the scope or identifying risks.
AriGarcia 👍 1 Selected: B
Preparation -> Identification Containment Eradication Recovery Lessons Learned
dnn_cbops 👍 1 Selected: A
From explanation in ComTIA security + Guide it is risk assessment
jbmac 👍 1 Selected: A
The correct answer is: A. Risk assessment Explanation: Risk assessment is the step in the risk management process that involves evaluating and identifying the potential risks associated with a project. This includes determining the scope of the project, identifying risks, analyzing their impact and likelihood, and helping to prioritize the risks based on their potential impact on the organization.
jennyka76 👍 2 Selected: B
The step in the risk management process that involves establishing the scope and potential risks involved with a project is called "Risk Identification

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding the Risk Management Lifecycle

CompTIA Security+ structures risk management into four distinct, sequential phases. Each phase has a specific purpose, and exam questions often test your ability to match keywords to the correct stage.

Why Risk Identification is Correct

Risk identification is the foundational step where you establish the context or scope of the project, define boundaries, and systematically catalog all potential threats, vulnerabilities, and assets. As community expert AriGarcia notes, this phase is essentially about listing possible threats before any numerical or qualitative analysis occurs. Setting the scope ensures that subsequent steps remain focused and aligned with organizational objectives.

Why Other Options Are Incorrect

Risk assessment (Option A) follows identification. It involves analyzing the identified risks to determine their likelihood, potential impact, and priority level. While some candidates argue that assessment includes identification, CompTIA strictly separates the two: identification gathers the data, and assessment evaluates it.

Risk treatment (Option C) focuses on selecting and implementing strategies to address prioritized risks, such as mitigation, avoidance, transfer, or acceptance. It does not involve scoping or initial discovery.

Risk monitoring and review (Option D) is a continuous process that tracks identified risks, measures control effectiveness, and updates the risk register as the environment changes. It occurs after treatment implementation, not at the project's outset.

Official Reference

Exam Strategy

When answering risk management questions, mentally map the four-phase cycle: Identify → Assess → Treat → Monitor. If the prompt contains words like 'scope,' 'list,' 'catalog,' or 'context,' choose Identification. If it mentions 'likelihood,' 'impact,' 'score,' or 'prioritize,' choose Assessment. This keyword mapping will help you quickly eliminate distractors.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide