nerdexam
(ISC)2

SSCP · Question #513

What can be best defined as the examination of threat sources against system vulnerabilities to determine the threats for a particular system in a particular operational environment?

The correct answer is C. Threat analysis. Threat analysis is the examination of threat sources against system vulnerabilities to determine the threats for a particular system in a particular operational environment. The following answers are incorrect: Risk analysis is the process of identifying the risks to system secur

Submitted by jian89· Apr 18, 2026Risk Identification, Monitoring and Analysis

Question

What can be best defined as the examination of threat sources against system vulnerabilities to determine the threats for a particular system in a particular operational environment?

Options

  • ARisk management
  • BRisk analysis
  • CThreat analysis
  • DDue diligence

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    92% (23)

Explanation

Threat analysis is the examination of threat sources against system vulnerabilities to determine the threats for a particular system in a particular operational environment. The following answers are incorrect: Risk analysis is the process of identifying the risks to system security and determining the probability of occurrence, the resulting impact, and the additional safeguards that mitigate this Risk analysis is synonymous with risk assessment and part of risk management, which is the ongoing process of assessing the risk to mission/business as part of a risk-based approach used to determine adequate security for a system by analyzing the threats and vulnerabilities and selecting appropriate, cost-effective controls to achieve and maintain an acceptable level or risk. Due Diligence is identifying possible risks that could affect a company based on best practices

Topics

#Threat analysis#Vulnerability#Risk assessment#Security concepts

Community Discussion

No community discussion yet for this question.

Full SSCP Practice