- Home
- All questions
- Question 100
CISSP study material · question 100 of 500
After a company hardens its externally facing portal, its attackers stop probing that portal and begin targeting a supplier with weaker controls instead. What does NIST SP 800-30 call this response?
Show the answer
Answer: A. Threat shifting in the target domain.
Threat shifting is the adversary's reaction to a control, changing timing, target, resources or method. Choosing a softer target is shifting in the target domain, not a transfer of risk.
Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 > 2.3.1 Threat Shifting