CISSP · Question #928
Which of the following combinations would MOST negatively affect availability?
The correct answer is A. Denial of Service (DoS) attacks and outdated hardware. Availability refers to ensuring systems and resources are accessible when needed. The combination that most directly and severely threatens availability involves active attacks that overwhelm systems combined with hardware failures that prevent recovery.
Question
Options
- ADenial of Service (DoS) attacks and outdated hardware
- BUnauthorized transactions and outdated hardware
- CFire and accidental changes to data
- DUnauthorized transactions and denial of service attacks
How the community answered
(27 responses)- A85% (23)
- B7% (2)
- C4% (1)
- D4% (1)
Why each option
Availability refers to ensuring systems and resources are accessible when needed. The combination that most directly and severely threatens availability involves active attacks that overwhelm systems combined with hardware failures that prevent recovery.
DoS attacks are specifically designed to exhaust system resources and make services unavailable to legitimate users, directly targeting availability. Outdated hardware compounds this threat by being more prone to failure, slower to respond under load, and lacking modern resilience features - creating a scenario where the system is simultaneously under attack and structurally weak, maximizing the negative impact on availability.
Unauthorized transactions primarily threaten integrity and confidentiality, not availability; while outdated hardware affects availability, pairing it with a non-availability threat makes this combination less impactful than A.
Fire is a physical threat to availability, but accidental changes to data primarily threaten integrity rather than availability, making this a mixed-pillar combination that does not maximally target availability.
While DoS attacks do threaten availability, unauthorized transactions target integrity and confidentiality rather than availability, so this pairing is less focused on availability than the DoS-plus-hardware-failure combination in option A.
Concept tested: CIA triad availability threats and attack combinations
Source: https://www.nist.gov/system/files/documents/2017/06/05/040-075.pdf
Topics
Community Discussion
No community discussion yet for this question.