nerdexam
PeopleCert

ITIL-4-DITS · Question #6

Which type of risk is MOST LIKELY to be identified by modeling and test reviews?

The correct answer is C. Cyber security risk. Cyber security risk is the correct answer because threat modeling and security test reviews are foundational techniques in cybersecurity risk identification - methods like STRIDE threat modeling and penetration test reviews are specifically designed to surface vulnerabilities…

Understand how to manage strategic capabilities

Question

Which type of risk is MOST LIKELY to be identified by modeling and test reviews?

Options

  • ADis risk
  • BEngagement risk
  • CCyber security risk
  • Dinnovation risk

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    84% (21)
  • D
    4% (1)

Explanation

Cyber security risk is the correct answer because threat modeling and security test reviews are foundational techniques in cybersecurity risk identification - methods like STRIDE threat modeling and penetration test reviews are specifically designed to surface vulnerabilities, attack vectors, and security weaknesses in systems before they can be exploited.

Engagement risk (B) is assessed through client due diligence, background checks, and professional judgment about a project relationship - not through technical modeling or test reviews.

Innovation risk (D) is evaluated via strategic business analysis, market research, and feasibility studies - modeling and test reviews don't map naturally to assessing the risks of adopting new ideas or technologies.

Dis risk (A) (likely disaster/disruption risk) is typically identified through environmental assessments, historical incident data, and business impact analysis - not structured modeling and test reviews.

Memory tip: Think "security teams model the threat, then test the defense." Modeling (threat modeling) + test reviews (pen test/security audit reviews) = the cybersecurity risk identification lifecycle. If you see both "modeling" and "test reviews" together, they're pointing at the security domain.

Topics

#risk management#cyber security risk#risk identification#modeling and testing

Community Discussion

No community discussion yet for this question.

Full ITIL-4-DITS Practice