Threat analysis:
An evaluation of the type, scope and nature of events or actions that can result in adverse consequences; identification of the threats that exist against enterprise assets
Scope Notes: The threat analysis usually defines the level of threat and the likelihood of it materializing.
Threat analysis: An evaluation of the type, scope and nature of events or actions. Directly from the 6th Manual. I cannot see the likelihood here. However, there is no better option.
The answer is Risk Analysis because that will give you estimated likelihood. Threat Analysis gives you potential harm.
Moreover, ISO/IEC 27005 Risk Analysis steps include Assessment of consequences | Assessment of incident likelihoods | Determination of level of risk.
upvoted 3 times
...
This section is not available anymore. Please use the main Exam Page.CRISC Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
[Removed]
5 months, 1 week agoCbtL
6 months, 3 weeks agojohn_boogieman
8 months, 2 weeks agoKozy
1 year agoRaj1510
1 year, 9 months agoendyendytse
2 years, 8 months agohussmohsin
2 years, 8 months agothedood
3 years, 1 month ago