nerdexam
(ISC)2

SSCP · Question #1221

Of the following, which is NOT a risk assessment system?

The correct answer is B. Information Security Protection Assessment Model (ISPAM). This question asks to identify which option is NOT a recognized risk assessment system or model.

Submitted by daniela_cl· Apr 18, 2026Risk Identification, Monitoring and Analysis

Question

Of the following, which is NOT a risk assessment system?

Options

  • AAggregated Countermeasures Effectiveness (ACE) Model
  • BInformation Security Protection Assessment Model (ISPAM)
  • CDollar-based OPSEC Risk Analysis (DORA)
  • DAnalysis of Networked Systems Security Risks (ANSSR)

How the community answered

(43 responses)
  • A
    5% (2)
  • B
    93% (40)
  • C
    2% (1)

Why each option

This question asks to identify which option is NOT a recognized risk assessment system or model.

AAggregated Countermeasures Effectiveness (ACE) Model

The Aggregated Countermeasures Effectiveness (ACE) Model is a documented approach used in risk assessment to evaluate the combined effectiveness of security countermeasures.

BInformation Security Protection Assessment Model (ISPAM)Correct

The 'Information Security Protection Assessment Model (ISPAM)' is not a commonly known or established risk assessment framework or system within cybersecurity literature or practice. The other options refer to actual, albeit sometimes specialized or historical, risk assessment methodologies.

CDollar-based OPSEC Risk Analysis (DORA)

Dollar-based OPSEC Risk Analysis (DORA) is a recognized quantitative risk analysis method that calculates risk in monetary terms, often for operational security.

DAnalysis of Networked Systems Security Risks (ANSSR)

Analysis of Networked Systems Security Risks (ANSSR) is a documented framework for assessing security risks specifically within networked environments.

Concept tested: Risk assessment methodologies

Topics

#Risk Assessment Models#Risk Analysis Methodologies#Information Security Risk

Community Discussion

No community discussion yet for this question.

Full SSCP Practice