nerdexam
Isaca

CISM · Question #154

The likelihood of a successful intrusion is a function of:

The correct answer is A. threat and vulnerability levels. The likelihood of a successful intrusion is primarily determined by the interplay between existing threats and the level of vulnerabilities present in a system or network. A threat exploits a vulnerability.

Submitted by jaden.t· Apr 18, 2026Information Security Risk Management

Question

The likelihood of a successful intrusion is a function of:

Options

  • Athreat and vulnerability levels.
  • Bdesign and redundancy of network perimeter controls.
  • Cconfiguration and maintenance of log monitoring system.
  • Dopportunity and asset value.

How the community answered

(18 responses)
  • A
    94% (17)
  • D
    6% (1)

Why each option

The likelihood of a successful intrusion is primarily determined by the interplay between existing threats and the level of vulnerabilities present in a system or network. A threat exploits a vulnerability.

Athreat and vulnerability levels.Correct

A successful intrusion occurs when a threat actor (threat) can exploit a weakness (vulnerability) in a system or network. Therefore, the likelihood of such an event is a direct function of the presence and potency of threats, combined with the number and severity of existing vulnerabilities.

Bdesign and redundancy of network perimeter controls.

While network perimeter controls reduce the likelihood of intrusion, they are a mitigation measure, not the fundamental factors defining the likelihood itself which are threat and vulnerability.

Cconfiguration and maintenance of log monitoring system.

Configuration and maintenance of log monitoring systems are crucial for detecting intrusions, but they do not directly determine the likelihood of the intrusion occurring in the first place.

Dopportunity and asset value.

Opportunity (e.g., attacker motivation, access) can influence a threat, and asset value determines the impact of a successful intrusion, but not the likelihood in the same direct technical sense as threat and vulnerability.

Concept tested: Risk assessment components (Threat x Vulnerability)

Source: https://learn.microsoft.com/en-us/security/benchmark/azure/security-controls-v2-introduction

Topics

#Risk Assessment#Threats#Vulnerabilities#Risk Likelihood

Community Discussion

No community discussion yet for this question.

Full CISM Practice