- Home
- All questions
- Question 216
CISM study material · question 216 of 1000
Which two graph-based techniques does SP 800-30 name for generating and bounding threat scenarios? Choose two.
Show the answer
Answer: C. Attack tree analysis for adversarial threats
B. Fault tree analysis for other types of threat
SP 800-30 names graph-based techniques including functional dependency network analysis, attack tree analysis for adversarial threats, and fault tree analysis for other types of threat, as ways to generate threat scenarios.
Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.3 Analysis Approaches