nerdexam
(ISC)2

CISSP · Question #928

Which of the following combinations would MOST negatively affect availability?

The correct answer is A. Denial of Service (DoS) attacks and outdated hardware. Availability refers to ensuring systems and resources are accessible when needed. The combination that most directly and severely threatens availability involves active attacks that overwhelm systems combined with hardware failures that prevent recovery.

Submitted by miguelv· Mar 5, 2026Security and Risk Management

Question

Which of the following combinations would MOST negatively affect availability?

Options

  • ADenial of Service (DoS) attacks and outdated hardware
  • BUnauthorized transactions and outdated hardware
  • CFire and accidental changes to data
  • DUnauthorized transactions and denial of service attacks

How the community answered

(27 responses)
  • A
    85% (23)
  • B
    7% (2)
  • C
    4% (1)
  • D
    4% (1)

Why each option

Availability refers to ensuring systems and resources are accessible when needed. The combination that most directly and severely threatens availability involves active attacks that overwhelm systems combined with hardware failures that prevent recovery.

ADenial of Service (DoS) attacks and outdated hardwareCorrect

DoS attacks are specifically designed to exhaust system resources and make services unavailable to legitimate users, directly targeting availability. Outdated hardware compounds this threat by being more prone to failure, slower to respond under load, and lacking modern resilience features - creating a scenario where the system is simultaneously under attack and structurally weak, maximizing the negative impact on availability.

BUnauthorized transactions and outdated hardware

Unauthorized transactions primarily threaten integrity and confidentiality, not availability; while outdated hardware affects availability, pairing it with a non-availability threat makes this combination less impactful than A.

CFire and accidental changes to data

Fire is a physical threat to availability, but accidental changes to data primarily threaten integrity rather than availability, making this a mixed-pillar combination that does not maximally target availability.

DUnauthorized transactions and denial of service attacks

While DoS attacks do threaten availability, unauthorized transactions target integrity and confidentiality rather than availability, so this pairing is less focused on availability than the DoS-plus-hardware-failure combination in option A.

Concept tested: CIA triad availability threats and attack combinations

Source: https://www.nist.gov/system/files/documents/2017/06/05/040-075.pdf

Topics

#availability#DoS attack#system reliability#outdated hardware

Community Discussion

No community discussion yet for this question.

Full CISSP Practice