SSCP · Question #1322
Total risk is defined as:
The correct answer is E. Threats * Vulnerability * Asset Value = Total Risk. Total risk is commonly understood as the potential harm to an asset resulting from the combination of a threat exploiting a vulnerability, weighted by the asset's value.
Question
Total risk is defined as:
Options
- AThreats * Vulnerability * Asset Control Gap = Total Risk
- BThreats * Vulnerability * Asset Replacement Cost = Total Risk
- CThreats * Estimated Downtime * Asset Value = Total Risk
- DTotal Risk = Asset Value * Exposure
- EThreats * Vulnerability * Asset Value = Total Risk
How the community answered
(23 responses)- B9% (2)
- D4% (1)
- E87% (20)
Why each option
Total risk is commonly understood as the potential harm to an asset resulting from the combination of a threat exploiting a vulnerability, weighted by the asset's value.
"Asset Control Gap" is not a standard component in the fundamental calculation of total risk.
"Asset Replacement Cost" is a factor in determining asset value but is not the sole component of asset value in the total risk formula.
"Estimated Downtime" is a factor in calculating impact but is not a direct component of the general formula for total risk itself.
While exposure is related to risk, the formula "Asset Value * Exposure" is not the most comprehensive or standard definition for total risk in cybersecurity.
Total risk is conceptually calculated as the product of all potential threats, the vulnerabilities that those threats could exploit, and the value of the asset being protected.
Concept tested: Risk calculation formula
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/risk-management
Topics
Community Discussion
No community discussion yet for this question.