ExamGecko
Question list
Search
Search

Question 474 - CISM discussion

Report
Export

Determining the risk for a particular threat/vulnerability pair before controls are applied can be expressed as:

A.
a function of the likelihood and impact, should a threat exploit a vulnerability.
Answers
A.
a function of the likelihood and impact, should a threat exploit a vulnerability.
B.
the magnitude of the impact, should a threat exploit a vulnerability.
Answers
B.
the magnitude of the impact, should a threat exploit a vulnerability.
C.
a function of the cost and effectiveness of controls over a vulnerability.
Answers
C.
a function of the cost and effectiveness of controls over a vulnerability.
D.
the likelihood of a given threat attempting to exploit a vulnerability
Answers
D.
the likelihood of a given threat attempting to exploit a vulnerability
Suggested answer: A

Explanation:

= According to the CISM Manual1, risk is defined as the combination of the probability of an event and its consequence. Therefore, determining the risk for a particular threat/vulnerability pair before controls are applied can be expressed as a function of the likelihood and impact, should a threat exploit a vulnerability. Likelihood is the probability or frequency of a threat occurring, while impact is the magnitude or severity of the harm or loss that would result from a threat exploiting a vulnerability. The higher the likelihood and impact, the higher the risk. The lower the likelihood and impact, the lower the risk.

The other options are not correct because they do not capture the full expression of risk. Option B only considers the impact, but not the likelihood, of a threat exploiting a vulnerability. Option C confuses the risk with the risk response, which is the action taken to reduce or mitigate the risk. Option D only considers the likelihood, but not the impact, of a threat attempting to exploit a vulnerability.

Reference= CISM Manual1, Chapter 2: Information Risk Management (IRM), Section 2.1: Risk Concepts2

1: https://store.isaca.org/s/store#/store/browse/cat/a2D4w00000Ac6NNEAZ/tiles2:2

asked 01/10/2024
Tr Skumar
55 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first