nerdexam
(ISC)2

CGRC · Question #403

In which step of the NIST SP 800-30 Risk Assessment process are vulnerabilities paired with threats? Response:

The correct answer is D. Impact Analysis. In the NIST SP 800-30 Risk Assessment process, vulnerabilities are paired with threats during the Impact Analysis step to determine the potential adverse effects resulting from a threat exploiting a vulnerability. This step focuses on understanding the magnitude of harm if a…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

In which step of the NIST SP 800-30 Risk Assessment process are vulnerabilities paired with threats? Response:

Options

  • ALikelihood Determination
  • BVulnerability Identification
  • CEvaluation and Assessment
  • DImpact Analysis

How the community answered

(33 responses)
  • B
    3% (1)
  • C
    3% (1)
  • D
    94% (31)

Why each option

In the NIST SP 800-30 Risk Assessment process, vulnerabilities are paired with threats during the Impact Analysis step to determine the potential adverse effects resulting from a threat exploiting a vulnerability. This step focuses on understanding the magnitude of harm if a threat-vulnerability pair materializes.

ALikelihood Determination

Likelihood Determination focuses on the probability that a threat will exploit a vulnerability, not the pairing itself.

BVulnerability Identification

Vulnerability Identification is the process of discovering weaknesses, not combining them with threats to determine consequences.

CEvaluation and Assessment

Evaluation and Assessment is a broader term that encompasses the entire risk assessment but is not the specific step where threats and vulnerabilities are initially paired for impact determination.

DImpact AnalysisCorrect

In the NIST SP 800-30 Risk Assessment process, Impact Analysis involves analyzing the potential adverse effects on organizational operations, assets, or individuals that could result if a threat source exploits a vulnerability. This step implicitly, if not explicitly, involves considering the specific vulnerabilities that threats could leverage to cause impact.

Concept tested: NIST SP 800-30 Impact Analysis

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#NIST SP 800-30#Risk Assessment Process#Impact Analysis#Threat-Vulnerability Pairing

Community Discussion

No community discussion yet for this question.

Full CGRC Practice