nerdexam
(ISC)2

CAP · Question #217

Which of the following NIST publications defines impact?

The correct answer is C. NIST SP 800-30. NIST SP 800-30, 'Guide for Conducting Risk Assessments,' defines key risk-related terms including 'impact,' which refers to the magnitude of harm that could result from a threat exploiting a vulnerability. NIST SP 800-41 covers firewall guidelines, NIST SP 800-37 describes the…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following NIST publications defines impact?

Options

  • ANIST SP 800-41
  • BNIST SP 800-37
  • CNIST SP 800-30
  • DNIST SP 800-53

How the community answered

(34 responses)
  • A
    3% (1)
  • C
    94% (32)
  • D
    3% (1)

Explanation

NIST SP 800-30, 'Guide for Conducting Risk Assessments,' defines key risk-related terms including 'impact,' which refers to the magnitude of harm that could result from a threat exploiting a vulnerability. NIST SP 800-41 covers firewall guidelines, NIST SP 800-37 describes the Risk Management Framework (RMF), and NIST SP 800-53 provides a catalog of security and privacy controls - none of which specifically define 'impact' as a primary focus.

Topics

#NIST SP 800-30#Risk Assessment#Impact Analysis#NIST Publications

Community Discussion

No community discussion yet for this question.

Full CAP Practice