350-201 · Question #87
A company's web server availability was breached by a DDoS attack and was offline for 3 hours because it was not deemed a critical asset in the incident response playbook. Leadership has requested a…
The correct answer is B. event severity and likelihood. To conduct an assessment the following steps are required: 1) Identify threat sources and events 2) Identify vulnerabilities and predisposing conditions 3) Determine likelihood of occurrence 4) Determine magnitude of impact 5) Determine risk…
Question
A company's web server availability was breached by a DDoS attack and was offline for 3 hours because it was not deemed a critical asset in the incident response playbook. Leadership has requested a risk assessment of the asset. An analyst conducted the risk assessment using the threat sources, events, and vulnerabilities. Which additional element is needed to calculate the risk?
Options
- Aassessment scope
- Bevent severity and likelihood
- Cincident response playbook
- Drisk model framework
How the community answered
(20 responses)- B85% (17)
- C5% (1)
- D10% (2)
Explanation
To conduct an assessment the following steps are required: 1) Identify threat sources and events 2) Identify vulnerabilities and predisposing conditions 3) Determine likelihood of occurrence 4) Determine magnitude of impact 5) Determine risk https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-30r1.pdf (page 32)
Topics
Community Discussion
No community discussion yet for this question.