(ISC)2(ISC)2
CAP · Question #298
CAP Question #298: Real Exam Question with Answer & Explanation
The correct answer is D: Residual Risk = Threats x Vulnerability x Asset Value x Control Gap. See the full explanation below for the reasoning.
Security and Privacy Governance, Risk Management, and Compliance Program
Question
Which of the following relations correctly describes residual risk?
Options
- AResidual Risk = Threats x Vulnerability x Asset Gap x Control Gap
- BResidual Risk = Threats x Exploit x Asset Value x Control Gap
- CResidual Risk = Threats x Exploit x Asset Value x Control Gap
- DResidual Risk = Threats x Vulnerability x Asset Value x Control Gap
Topics
#Residual Risk#Risk Calculation#Control Effectiveness#Risk Components
Community Discussion
No community discussion yet for this question.