- Home
- All questions
- Question 354
CISM study material · question 354 of 1000
A team completes vulnerability identification and discovers weaknesses that suggest attack paths nobody had listed as threat events. What does SP 800-30 say about this?
Show the answer
Answer: B. Iteration among the assessment tasks is both necessary and expected
SP 800-30 presents the tasks sequentially for clarity but states some iteration among them is both necessary and expected, giving the example that identifying vulnerabilities may reveal additional threat events.
Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 3.2 Conducting the Risk Assessment