59.7k views
5 votes
What is meant by exposure factor ( EF)?

a. The probability that a particular threat will exploit an IT vulnerability causing harm to an organization.
b. This is measured in terms of probability and consequence.
c. The expected amount of damage that an asset would incur if a risk materialized; normally described as a percentage.
d. The number of times per year you expect a compromise to occur.
e. A potential attack on a system.

User Jmroyalty
by
5.6k points

1 Answer

6 votes

Answer:

c

Step-by-step explanation:

Exposure factor is the impact of a risk over an asset or the potential loss to an asset in the case of a risk. It is usually represented as percentage. Exposure Factor can be calculated in relation to a specific threat or risk such as security threat or fire.

Therefore, option C, the expected amount of damage that an asset would incur if a risk materialized is the correct choice.

User Sreeramu
by
5.9k points