In risk assessment, how is likelihood defined and estimated?

Prepare for the Integrated Defense Test 1 with our comprehensive quiz. Utilize flashcards, multiple-choice questions, and detailed explanations for each answer to ensure you're fully prepared for your exam!

Multiple Choice

In risk assessment, how is likelihood defined and estimated?

Explanation:
Likelihood in risk assessment is the probability that a threat will exploit a vulnerability, considering what attackers can do and how defenses may stop them. This probability is estimated from historical data on past exploits, threat modeling that maps out realistic attack paths, and evaluations of how effective current controls are at preventing or detecting exploitation. When historical incidents are frequent, attack paths are straightforward, and controls are weak, the likelihood is higher. Strong controls and solid threat modeling lower the chance of successful exploitation. The other options mix up what likelihood measures: damage potential describes impact, not probability; the number of vulnerabilities reflects exposure but not the probability of exploitation; and patch time affects how long a vulnerability is exposed and can influence likelihood indirectly, but is not the probability itself.

Likelihood in risk assessment is the probability that a threat will exploit a vulnerability, considering what attackers can do and how defenses may stop them. This probability is estimated from historical data on past exploits, threat modeling that maps out realistic attack paths, and evaluations of how effective current controls are at preventing or detecting exploitation. When historical incidents are frequent, attack paths are straightforward, and controls are weak, the likelihood is higher. Strong controls and solid threat modeling lower the chance of successful exploitation. The other options mix up what likelihood measures: damage potential describes impact, not probability; the number of vulnerabilities reflects exposure but not the probability of exploitation; and patch time affects how long a vulnerability is exposed and can influence likelihood indirectly, but is not the probability itself.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy