nerdexam
(ISC)2

CGRC · Question #298

Process of formally evaluating the degree of threat to an information system or enterprise and describing the nature of the threat. Response:

The correct answer is A. Threat Assessment. This definition precisely describes a threat assessment, which involves systematically evaluating potential threats, their likelihood, and their potential impact on an information system or enterprise.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Process of formally evaluating the degree of threat to an information system or enterprise and describing the nature of the threat. Response:

Options

  • AThreat Assessment
  • BThreat Event
  • CThreat Source
  • DThreat Scenario

How the community answered

(58 responses)
  • A
    91% (53)
  • B
    5% (3)
  • C
    2% (1)
  • D
    2% (1)

Why each option

This definition precisely describes a threat assessment, which involves systematically evaluating potential threats, their likelihood, and their potential impact on an information system or enterprise.

AThreat AssessmentCorrect

A threat assessment is a systematic process of identifying and evaluating potential threats, their characteristics, capabilities, and the likelihood they will materialize, to an organization's information systems or assets. Its purpose is to understand the nature of these threats, including their origins and potential impact, enabling informed risk management decisions.

BThreat Event

A threat event is an occurrence or incident that results from a threat being actualized, not the process of evaluating threats.

CThreat Source

A threat source is the origin or actor responsible for a potential threat, such as a hacker group or a natural disaster, not the assessment process itself.

DThreat Scenario

A threat scenario is a hypothetical situation describing how a specific threat might exploit a vulnerability, used for planning or testing, not the formal evaluation process.

Concept tested: Risk management - threat assessment

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#Threat Assessment#Risk Management#Threat Evaluation#Information Security

Community Discussion

No community discussion yet for this question.

Full CGRC Practice