ITPEC IP October 2023 Question 43

Source exam: ITPEC IP October 2023Topic: Security

ITPEC IP October 2023 — Question 43 of 100

Within the scope of an ISMS, risks are identified that could harm confidentiality, integrity, or availability. These three properties form the CIA triad: confidentiality prevents unauthorized disclosure, integrity prevents improper alteration or destruction, and availability ensures authorized access when needed. Thus A is “In the scope” and B is “integrity.”

Answer (c)

Why not others:
- Risks outside the defined ISMS scope are not the objects of that ISMS risk-identification activity

- Vulnerability is a weakness that a threat may exploit; it is not one of the three information-security properties paired with confidentiality and availability

Key rule: Information-security risk assessment within scope evaluates threats to confidentiality, integrity, and availability.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.