Study. uk . com
  1. Home
  2. All questions
  3. Question 181

CISM study material · question 181 of 1000

An analyst wants to model how a breach would actually unfold rather than listing isolated events. Which SP 800-30 construct is designed for this?

  1. A threat scenario — a time-ordered set of discrete threat events attributed to one or more sources
  2. An exposure rating
  3. A risk model
  4. A predisposing condition, which records the factors already present that make a particular adverse impact more likely to arise
Show the answer

Answer: A. A threat scenario — a time-ordered set of discrete threat events attributed to one or more sources

SP 800-30 builds a threat scenario out of separate events, laid out in the order they occur and traced back to one source or several, ending in adverse effect. That ordering is what a bare event list lacks.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.1 Risk Models — Threats

Challenge yourself on this topic → Study as cards