Study. uk . com
  1. Home
  2. All questions
  3. Question 215

CISM study material · question 215 of 1000

Which two many-to-many relationships does SP 800-30 identify in risk analysis? Choose two.

  1. One threat event may strike several assets or produce several distinct impacts
  2. A single vulnerability can be exploited by only one threat event, which is why pairing them is one-to-one
  3. A single asset can be affected by only one kind of threat event at a time
  4. A single threat event can exploit multiple vulnerabilities
Show the answer

Answer: D. A single threat event can exploit multiple vulnerabilities
A. One threat event may strike several assets or produce several distinct impacts

SP 800-30 records many-to-many links in three places: sources to events, events to vulnerabilities, and events to the assets and impacts they touch.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.3 Analysis Approaches

Challenge yourself on this topic → Study as cards