CISSP · Question #1526
Drag and Drop Question Drag the following Security Engineering terms on the left to the BEST definition on the right. Answer:
The correct answer is Risk; Security Risk Treatment; Protection Needs Assessment; Threat Assessment. These four terms represent a sequential and hierarchical framework in Security Engineering: Risk is the foundational concept combining likelihood and impact of a threat exploiting a vulnerability; Threat Assessment identifies and evaluates potential threats to a system…
Question
Exhibit
Answer Area
Drag items
Correct arrangement
- Risk
- Security Risk Treatment
- Protection Needs Assessment
- Threat Assessment
Explanation
These four terms represent a sequential and hierarchical framework in Security Engineering: Risk is the foundational concept combining likelihood and impact of a threat exploiting a vulnerability; Threat Assessment identifies and evaluates potential threats to a system; Protection Needs Assessment determines what assets require safeguarding and to what degree; and Security Risk Treatment defines the chosen response strategy (accept, mitigate, transfer, or avoid) after risks are identified and assessed. Each term occupies a distinct and non-interchangeable role in the security engineering lifecycle, making their correct mapping critical to understanding the discipline.
Topics
Community Discussion
No community discussion yet for this question.
