nerdexam
(ISC)2

CISSP · Question #1526

Drag and Drop Question Drag the following Security Engineering terms on the left to the BEST definition on the right. Answer:

The correct answer is Risk; Security Risk Treatment; Protection Needs Assessment; Threat Assessment. These four terms represent a sequential and hierarchical framework in Security Engineering: Risk is the foundational concept combining likelihood and impact of a threat exploiting a vulnerability; Threat Assessment identifies and evaluates potential threats to a system…

Submitted by anjalisingh· Mar 5, 2026Security Engineering and Risk Management - Understanding core security engineering terminology and the relationships between risk identification, assessment, protection planning, and risk treatment within a structured security framework (aligned with CISSP, CSSLP, or similar certifications).

Question

Drag and Drop Question Drag the following Security Engineering terms on the left to the BEST definition on the right. Answer:

Exhibit

CISSP question #1526 exhibit

Answer Area

Drag items

RiskSecurity Risk TreatmentProtection Needs AssessmentThreat Assessment

Correct arrangement

  • Risk
  • Security Risk Treatment
  • Protection Needs Assessment
  • Threat Assessment

Explanation

These four terms represent a sequential and hierarchical framework in Security Engineering: Risk is the foundational concept combining likelihood and impact of a threat exploiting a vulnerability; Threat Assessment identifies and evaluates potential threats to a system; Protection Needs Assessment determines what assets require safeguarding and to what degree; and Security Risk Treatment defines the chosen response strategy (accept, mitigate, transfer, or avoid) after risks are identified and assessed. Each term occupies a distinct and non-interchangeable role in the security engineering lifecycle, making their correct mapping critical to understanding the discipline.

Topics

#Security Engineering#Risk Management#Threat Assessment#Protection Needs

Community Discussion

No community discussion yet for this question.

Full CISSP Practice