Study. uk . com
  1. Home
  2. All questions
  3. Question 354

CISM study material · question 354 of 1000

A team completes vulnerability identification and discovers weaknesses that suggest attack paths nobody had listed as threat events. What does SP 800-30 say about this?

  1. The new events must wait for the next assessment cycle
  2. Iteration among the assessment tasks is both necessary and expected
  3. The task order has been performed incorrectly
  4. Only threat events identified before the vulnerability task may be assessed in this cycle
Show the answer

Answer: B. Iteration among the assessment tasks is both necessary and expected

SP 800-30 presents the tasks sequentially for clarity but states some iteration among them is both necessary and expected, giving the example that identifying vulnerabilities may reveal additional threat events.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 3.2 Conducting the Risk Assessment

Challenge yourself on this topic → Study as cards