Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IIBA-CCA Exam - Topic 2 Question 11 Discussion

What risk factors should the analyst consider when assessing the Overall Likelihood of a threat?
A) Attack Initiation Likelihood and Initiated Attack Success Likelihood
B) Risk Level, Risk Impact, and Mitigation Strategy
C) Overall Site Traffic and Commerce Volume
D) Past Experience and Trends

IIBA-CCA Exam - Topic 2 Question 11 Discussion

Actual exam question for IIBA's IIBA-CCA exam
Question #: 11
Topic #: 2
[All IIBA-CCA Questions]

What risk factors should the analyst consider when assessing the Overall Likelihood of a threat?

Show Suggested Answer Hide Answer
Suggested Answer: A

In NIST-style risk assessment, overall likelihood is not a single guess; it is derived by considering two related likelihood components. First is the likelihood that a threat event will be initiated. This reflects how probable it is that a threat actor or source will attempt the attack or that a threat event will occur, considering factors such as adversary capability, intent, targeting, opportunity, and environmental conditions. Second is the likelihood that an initiated event will succeed, meaning the attempt results in the adverse outcome. This depends heavily on the organization's existing protections and conditions, including control strength, system exposure, vulnerabilities, misconfigurations, detection and response capability, and user behavior.

Option A matches this structure: analysts evaluate both attack initiation likelihood and initiated attack success likelihood to reach an overall view of likelihood. A high initiation likelihood with low success likelihood might occur when an organization is frequently targeted but has strong defenses. Conversely, low initiation likelihood with high success likelihood might apply to niche systems that are rarely targeted but poorly protected.

The other options are incomplete or misplaced. Risk impact is a separate dimension from likelihood, and mitigation strategy is an output of risk treatment, not an input to likelihood. Site traffic and commerce volume can influence exposure but do not define likelihood by themselves. Past experience and trends are useful evidence, but they support estimating the two likelihood components rather than replacing them.


Contribute your Thoughts:

0/2000 characters
Harley
4 days ago
Totally agree with A, initiation likelihood is crucial!
upvoted 0 times
...
Lou
9 days ago
Surprised that C is even an option, seems irrelevant.
upvoted 0 times
...
Sharen
14 days ago
I think B is super important too, can't overlook risk impact.
upvoted 0 times
...
Evan
19 days ago
Definitely A and D are key factors!
upvoted 0 times
...
Remona
24 days ago
I feel like risk level and impact are crucial, but I’m not sure how mitigation strategies fit into the overall likelihood assessment.
upvoted 0 times
...
Rene
29 days ago
I’m a bit confused about whether overall site traffic really impacts threat likelihood. It seems relevant, but I can't recall specifics.
upvoted 0 times
...
Dierdre
1 month ago
I remember a practice question that focused on attack initiation likelihood, so I feel like option A might be important too.
upvoted 0 times
...
Rory
1 month ago
I think the risk factors should definitely include past experience and trends, but I'm not sure if that's the only thing to consider.
upvoted 0 times
...

Save Cancel