Study. uk . com
  1. Home
  2. All questions
  3. Question 216

CISM study material · question 216 of 1000

Which two graph-based techniques does SP 800-30 name for generating and bounding threat scenarios? Choose two.

  1. Control self-assessment questionnaires
  2. Fault tree analysis for other types of threat
  3. Attack tree analysis for adversarial threats
  4. Regression analysis of historical loss data
Show the answer

Answer: C. Attack tree analysis for adversarial threats
B. Fault tree analysis for other types of threat

SP 800-30 names graph-based techniques including functional dependency network analysis, attack tree analysis for adversarial threats, and fault tree analysis for other types of threat, as ways to generate threat scenarios.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.3 Analysis Approaches

Challenge yourself on this topic → Study as cards