CISM · Question #154
The likelihood of a successful intrusion is a function of:
The correct answer is A. threat and vulnerability levels. The likelihood of a successful intrusion is primarily determined by the interplay between existing threats and the level of vulnerabilities present in a system or network. A threat exploits a vulnerability.
Question
The likelihood of a successful intrusion is a function of:
Options
- Athreat and vulnerability levels.
- Bdesign and redundancy of network perimeter controls.
- Cconfiguration and maintenance of log monitoring system.
- Dopportunity and asset value.
How the community answered
(18 responses)- A94% (17)
- D6% (1)
Why each option
The likelihood of a successful intrusion is primarily determined by the interplay between existing threats and the level of vulnerabilities present in a system or network. A threat exploits a vulnerability.
A successful intrusion occurs when a threat actor (threat) can exploit a weakness (vulnerability) in a system or network. Therefore, the likelihood of such an event is a direct function of the presence and potency of threats, combined with the number and severity of existing vulnerabilities.
While network perimeter controls reduce the likelihood of intrusion, they are a mitigation measure, not the fundamental factors defining the likelihood itself which are threat and vulnerability.
Configuration and maintenance of log monitoring systems are crucial for detecting intrusions, but they do not directly determine the likelihood of the intrusion occurring in the first place.
Opportunity (e.g., attacker motivation, access) can influence a threat, and asset value determines the impact of a successful intrusion, but not the likelihood in the same direct technical sense as threat and vulnerability.
Concept tested: Risk assessment components (Threat x Vulnerability)
Source: https://learn.microsoft.com/en-us/security/benchmark/azure/security-controls-v2-introduction
Topics
Community Discussion
No community discussion yet for this question.