SSCP · Question #1221
Of the following, which is NOT a risk assessment system?
The correct answer is B. Information Security Protection Assessment Model (ISPAM). This question asks to identify which option is NOT a recognized risk assessment system or model.
Question
Of the following, which is NOT a risk assessment system?
Options
- AAggregated Countermeasures Effectiveness (ACE) Model
- BInformation Security Protection Assessment Model (ISPAM)
- CDollar-based OPSEC Risk Analysis (DORA)
- DAnalysis of Networked Systems Security Risks (ANSSR)
How the community answered
(43 responses)- A5% (2)
- B93% (40)
- C2% (1)
Why each option
This question asks to identify which option is NOT a recognized risk assessment system or model.
The Aggregated Countermeasures Effectiveness (ACE) Model is a documented approach used in risk assessment to evaluate the combined effectiveness of security countermeasures.
The 'Information Security Protection Assessment Model (ISPAM)' is not a commonly known or established risk assessment framework or system within cybersecurity literature or practice. The other options refer to actual, albeit sometimes specialized or historical, risk assessment methodologies.
Dollar-based OPSEC Risk Analysis (DORA) is a recognized quantitative risk analysis method that calculates risk in monetary terms, often for operational security.
Analysis of Networked Systems Security Risks (ANSSR) is a documented framework for assessing security risks specifically within networked environments.
Concept tested: Risk assessment methodologies
Topics
Community Discussion
No community discussion yet for this question.