nerdexam
(ISC)2

CGRC · Question #252

The intent and method targeted at the intentional exploitation of a vulnerability or a situation and method that may accidentally trigger a vulnerability. Synonymous with Threat Agent. Response:

The correct answer is A. Threat Source. A threat source describes the intent and method used to exploit a vulnerability, whether intentionally or accidentally, and is synonymous with a threat agent.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The intent and method targeted at the intentional exploitation of a vulnerability or a situation and method that may accidentally trigger a vulnerability. Synonymous with Threat Agent. Response:

Options

  • AThreat Source
  • BThreat Event
  • CThreat Assessment
  • DThreat Scenario

How the community answered

(23 responses)
  • A
    96% (22)
  • C
    4% (1)

Why each option

A threat source describes the intent and method used to exploit a vulnerability, whether intentionally or accidentally, and is synonymous with a threat agent.

AThreat SourceCorrect

A threat source, often interchangeable with threat agent, is the entity that causes a threat event to occur, possessing the intent and method to exploit a vulnerability. This definition clearly aligns with the description of an entity intentionally or accidentally triggering a vulnerability.

BThreat Event

A threat event is the actual occurrence of an undesirable incident that has a negative impact on an information system or organization, not the source itself.

CThreat Assessment

A threat assessment is a process of identifying and evaluating potential threats, not the entity that poses the threat.

DThreat Scenario

A threat scenario is a hypothetical description of how a threat event could occur, including the actors, assets, and vulnerabilities involved, not the source of the threat.

Concept tested: Cybersecurity threat terminology

Source: https://csrc.nist.gov/glossary/term/threat-source

Topics

#Threat Source#Risk Management Terminology#NIST RMF

Community Discussion

No community discussion yet for this question.

Full CGRC Practice