Study. uk . com
  1. Home
  2. All questions
  3. Question 100

CISSP study material · question 100 of 500

After a company hardens its externally facing portal, its attackers stop probing that portal and begin targeting a supplier with weaker controls instead. What does NIST SP 800-30 call this response?

  1. Threat shifting in the target domain.
  2. A predisposing condition in the supply chain.
  3. Residual risk crystallising after mitigation.
  4. Risk transference to a third party.
Show the answer

Answer: A. Threat shifting in the target domain.

Threat shifting is the adversary's reaction to a control, changing timing, target, resources or method. Choosing a softer target is shifting in the target domain, not a transfer of risk.

Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 > 2.3.1 Threat Shifting

Challenge yourself on this topic → Study as cards