nerdexam
Cisco

350-201 · Question #87

A company's web server availability was breached by a DDoS attack and was offline for 3 hours because it was not deemed a critical asset in the incident response playbook. Leadership has requested a…

The correct answer is B. event severity and likelihood. To conduct an assessment the following steps are required: 1) Identify threat sources and events 2) Identify vulnerabilities and predisposing conditions 3) Determine likelihood of occurrence 4) Determine magnitude of impact 5) Determine risk…

Security Policies and Procedures

Question

A company's web server availability was breached by a DDoS attack and was offline for 3 hours because it was not deemed a critical asset in the incident response playbook. Leadership has requested a risk assessment of the asset. An analyst conducted the risk assessment using the threat sources, events, and vulnerabilities. Which additional element is needed to calculate the risk?

Options

  • Aassessment scope
  • Bevent severity and likelihood
  • Cincident response playbook
  • Drisk model framework

How the community answered

(20 responses)
  • B
    85% (17)
  • C
    5% (1)
  • D
    10% (2)

Explanation

To conduct an assessment the following steps are required: 1) Identify threat sources and events 2) Identify vulnerabilities and predisposing conditions 3) Determine likelihood of occurrence 4) Determine magnitude of impact 5) Determine risk https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-30r1.pdf (page 32)

Topics

#risk assessment#risk calculation#likelihood#threat events

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice