Study. uk . com
  1. Home
  2. All questions
  3. Question 1

CompTIA Security+ study material · question 1 of 611

A security team rates a finding as high risk purely because the potential loss would be severe, without considering how plausible the event is. Which part of the standard definition of risk have they left out?

  1. The cost of the control that would fix it
  2. The likelihood that the event occurs
  3. The identity of the threat actor
  4. The number of assets involved
Show the answer

Answer: B. The likelihood that the event occurs

Risk combines impact with likelihood. Impact alone describes a worst case, not a risk rating.

Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 § 2.3 The Fundamentals

Challenge yourself on this topic → Study as cards