CAS-003 · Question #867
Which of the following is the primary cybersecurity-related difference between the goals of a risk assessment and a business impact analysis?
The correct answer is A. Broad spectrum threat analysis. The primary cybersecurity-related difference between a risk assessment and a BIA (Business Impact Analysis) is scope. A risk assessment performs a broad spectrum threat analysis - it examines a wide range of threat sources, vulnerabilities, and attack vectors across the entire…
Question
Which of the following is the primary cybersecurity-related difference between the goals of a risk assessment and a business impact analysis?
Options
- ABroad spectrum threat analysis
- BAdherenece to quantitative vs. qualitative methods
- CA focus on current state without regard to cost
- DMeasurements of ALE vs.SLE and downtime
How the community answered
(52 responses)- A90% (47)
- B6% (3)
- C2% (1)
- D2% (1)
Explanation
The primary cybersecurity-related difference between a risk assessment and a BIA (Business Impact Analysis) is scope. A risk assessment performs a broad spectrum threat analysis - it examines a wide range of threat sources, vulnerabilities, and attack vectors across the entire organization and evaluates their likelihood and potential impact. A BIA, by contrast, focuses specifically on the operational consequences of disruptions to critical business functions, emphasizing recovery time objectives (RTO), recovery point objectives (RPO), and financial impact. The BIA assumes something bad happens and asks 'how bad is it for the business?' while the risk assessment asks 'what threats exist and how likely are they?' Option D (ALE vs. SLE) relates to quantitative risk metrics, not the core distinction between these two processes.
Topics
Community Discussion
No community discussion yet for this question.