Study. uk . com
  1. Home
  2. All questions
  3. Question 179

CISM study material · question 179 of 1000

How does SP 800-30 characterise a threat source?

  1. Either by intent and method aimed at exploiting a vulnerability, or by a situation and method that might exploit one accidentally
  2. Only by the technical capability needed to exploit a known weakness, which is why any source that does not hold that capability is left out of the model entirely
  3. Only by deliberate intent to cause harm, which is why accidental and environmental sources are recorded elsewhere in the assessment instead
  4. By the magnitude of harm it has caused historically, so a source with no recorded losses against it is treated as carrying no threat at all
Show the answer

Answer: A. Either by intent and method aimed at exploiting a vulnerability, or by a situation and method that might exploit one accidentally

SP 800-30 characterises a threat source as the intent and method targeted at exploiting a vulnerability, or a situation and method that may accidentally exploit one, which is what admits non-adversarial sources.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.1 Risk Models — Threats

Challenge yourself on this topic → Study as cards