nerdexam
(ISC)2

SSCP · Question #1276

Threat assessment has four major components, name them. (Choose four)

The correct answer is A. Type B. Mechanism C. Impact D. Probability. Threat assessment typically involves identifying the type of threat, its mechanism, the potential impact, and the probability of its occurrence.

Submitted by valeria.br· Apr 18, 2026Risk Identification, Monitoring and Analysis

Question

Threat assessment has four major components, name them. (Choose four)

Options

  • AType
  • BMechanism
  • CImpact
  • DProbability
  • EALE - Annual Loss Expectancy

How the community answered

(24 responses)
  • A
    92% (22)
  • E
    8% (2)

Why each option

Threat assessment typically involves identifying the type of threat, its mechanism, the potential impact, and the probability of its occurrence.

ATypeCorrect

The 'Type' component of threat assessment identifies the nature or category of the threat, such as malware, social engineering, or a natural disaster.

BMechanismCorrect

The 'Mechanism' component describes how the threat operates or is delivered, detailing the specific methods or vectors used by the threat actor or event.

CImpactCorrect

The 'Impact' component evaluates the potential consequences or damage that could result if the threat materializes, considering effects on confidentiality, integrity, and availability.

DProbabilityCorrect

The 'Probability' component assesses the likelihood or frequency of the threat occurring, often based on historical data, known vulnerabilities, or expert judgment.

EALE - Annual Loss Expectancy

ALE (Annual Loss Expectancy) is a quantitative financial measure of risk, often derived from impact and probability, but it is an outcome or calculation in risk assessment, not one of the fundamental descriptive components of the threat itself.

Concept tested: Threat assessment components, risk analysis

Source: https://www.nist.gov/cyberframework/risk-management-process/threat-and-vulnerability-management

Topics

#Threat assessment#Risk components#Security risk analysis#Threat evaluation

Community Discussion

No community discussion yet for this question.

Full SSCP Practice