Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 34 discussion

Actual exam question from ISC's CISSP
Question #: 34
Topic #: 1
[All CISSP Questions]

Which of the following is security control volatility?

  • A. A reference to the impact of the security control.
  • B. A reference to the likelihood of change in the security control.
  • C. A reference to how unpredictable the security control is.
  • D. A reference to the stability of the security control.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
SongOTD
Highly Voted 2 years, 1 month ago
Selected Answer: B
https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-137.pdf It says Security control volatility is a measure of how frequently a control is likely to change over time subsequent to its implementation. So I would choose B.
upvoted 11 times
jackdryan
1 year, 7 months ago
B is correct
upvoted 2 times
...
...
Fouad777
Most Recent 6 days, 8 hours ago
The correct answer is: B. A reference to the likelihood of change in the security control. Explanation: Security control volatility refers to the likelihood or frequency of change in a security control over time. Some controls, such as policies or procedures, tend to be more stable and change less frequently. Others, like technical controls (e.g., firewall rules or antivirus definitions), may change often to respond to evolving threats, updates, or operational requirements. Understanding the volatility of a control helps in planning and prioritizing maintenance, audits, and updates to ensure the control remains effective over time.
upvoted 1 times
...
robervalchocolat
2 months, 3 weeks ago
Security control volatility refers to the likelihood that a security control will need to be changed or updated in the future. This can be due to various factors, such as changes in technology, threats, or organizational needs.
upvoted 1 times
...
25cbb5f
7 months, 3 weeks ago
The correct answer is B. A reference to the likelihood of change in the security control. Here's what security control volatility means: Definition: Security control volatility refers to how frequently a security control might need to be changed or updated over time. This could be due to factors like: Evolving threats and vulnerabilities Changes in technology New regulations or compliance requirements Organizational shifts in business needs Why other options are not correct: A. A reference to the impact of the security control: Impact refers to the potential consequences or effects of the security control itself, not its volatility. C. A reference to how unpredictable the security control is: Unpredictability implies randomness or a lack of reliability, which is not the focus of volatility. D. A reference to the stability of the security control: Stability is the opposite of volatility. A control with low volatility would be considered more stable.
upvoted 1 times
...
Vaneck
8 months, 1 week ago
Selected Answer: D
The correct answer is D. A reference to the stability of the safety control. The volatility of a safety control refers to its stability and ability to remain effective and constant over time without the need for frequent modifications.
upvoted 1 times
...
DarkHorseVIII
9 months, 1 week ago
Answer is C. ---Kinda like stocks: Penny stocks are very volatile; they go up and down very fast because of how cheap they are. They are very unpredictable.
upvoted 1 times
...
Demo25
1 year, 4 months ago
Selected Answer: B
The other options are incorrect. A. Impact of the security control refers to the severity of the impact that a security control can have on an organization if it is not properly implemented or maintained. C. Unpredictability of the security control refers to how difficult it is to predict how a security control will behave in a given situation. D. Stability of the security control refers to how resistant a security control is to change. Therefore, the correct answer is B. A reference to the likelihood of change in the security control.
upvoted 3 times
...
Bach1968
1 year, 4 months ago
Security control volatility refers to the likelihood of change in the security control. Therefore, option B: A reference to the likelihood of change in the security control is the correct description of security control volatility. Options A, C, and D are not accurate descriptions of security control volatility: Option A: A reference to the impact of the security control does not relate directly to volatility but rather focuses on the effect or effectiveness of the control. Option C: A reference to how unpredictable the security control is does not capture the essence of volatility, which pertains more to the likelihood of change rather than the unpredictability of the control itself. Option D: A reference to the stability of the security control is not synonymous with volatility. Stability refers to the consistent performance and reliability of the control over time, whereas volatility specifically refers to the potential for changes.
upvoted 1 times
...
jackdryan
1 year, 7 months ago
B is correct
upvoted 1 times
...
s_n_
1 year, 10 months ago
Answer B: Security control volatility is a term used to refer to the likelihood of change in security control. This is an important concept to consider, as it can impact the effectiveness of a security control over time. Resources that provide further information on security control volatility include the National Institute of Standards and Technology (NIST) Security Control Volatility Framework and the International Organization for Standardization (ISO) 27000 series of standards.
upvoted 1 times
...
Dee83
1 year, 10 months ago
B. Correct answer A reference to the likelihood of change in the security control is security control volatility. Security control volatility refers to the likelihood of change in the security control. It represents how frequently a security control may change or need to be updated to reflect new security threats or business requirements. Security controls that are volatile, such as firewalls, intrusion detection systems, and antivirus software, require more frequent monitoring and updating to ensure that they continue to provide adequate protection. High volatility controls may require more resources and effort to maintain their effectiveness. On the other hand, low volatility controls, such as security policies, may not require as much attention, but still need to be reviewed periodically to ensure that they are still effective and aligned with the organization's needs.
upvoted 1 times
...
somkiatr
1 year, 11 months ago
Selected Answer: B
Security control volatility is a measure of how frequently a control is likely to change over time subsequent to its implementation. Reference --> NIST SP 800-137, Information Security Continuous Monitoring. https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-137.pdf
upvoted 1 times
...
Firedragon
2 years ago
Selected Answer: B
B. https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-137.pdf Security control volatility is a measure of how frequently a control is likely to change over time subsequent to its implementation.
upvoted 1 times
...
rootic
2 years ago
Selected Answer: B
Going with B.
upvoted 1 times
...
Eltooth
2 years ago
Selected Answer: B
B is correct answer.
upvoted 1 times
...
DragonHunter40
2 years, 1 month ago
Volatility means unpredictable.
upvoted 2 times
...
Junah
2 years, 2 months ago
I agree with B
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...