200-201 Question 41
Select 2A cybersecurity analyst at your organization has conducted a risk assessment for a newly implemented web application. The assessment identified several risks, including a vulnerability that could allow attackers to inject malicious code. The analyst suggests using a risk scoring system to prioritize addressing these risks. Which of the following factors should the analyst consider when scoring this risk?
- A
The potential impact on the organization if the vulnerability is exploited
- B
The cost of mitigating the risk compared to the potential loss
- C
The likelihood of the vulnerability being exploited
- D
The number of users interacting with the application daily
- E
The reputation of the vendor that developed the application
Show answer and explanation
Correct answers: A, C
Explanation
Risk scoring involves evaluating both the potential impact of a risk and the likelihood of its occurrence. These two factors help prioritize which risks need to be addressed first. While other considerations, such as cost and application usage, may influence decision-making later, they are not part of the risk scoring process itself.
- A. Correct.
The potential impact on the organization is a critical factor in risk scoring because it helps quantify the severity of the consequences if the risk materializes.
- B. Incorrect.
While cost is an important consideration for risk mitigation planning, it is not directly used in the scoring process of a risk assessment.
- C. Correct.
The likelihood of exploitation is a core component of risk scoring as it measures the probability of the risk occurring.
- D. Incorrect.
The number of users interacting with the application is not directly relevant to risk scoring, though it could be considered for prioritization in some cases.
- E. Incorrect.
The reputation of the vendor is not related to the inherent risk of the vulnerability or its scoring.