A manager asks how the security team decides which issue should be fixed first. Which two factors are MOST important to evaluate for each risk?
Trap 1: Asset age and user satisfaction
Asset age and user satisfaction do not quantify likelihood or impact, so they cannot order remediation work. They are tempting because ageing hardware correlates with failure and satisfaction signals service quality, but risk prioritisation requires likelihood and impact values, which these attributes do not provide.
Trap 2: Vendor popularity and implementation speed
Vendor popularity and implementation speed say nothing about likelihood or business impact, so they cannot rank risks for remediation. They are tempting because procurement and rollout planning genuinely weigh vendor adoption and deployment timelines, but prioritisation requires likelihood and impact scores, not supplier metrics.
Trap 3: Encryption algorithm and screen resolution
Encryption algorithm and screen resolution are technical and display attributes, not risk-ranking inputs; neither expresses likelihood or impact. They tempt because cryptographic strength matters in control selection and resolution in endpoint standards, yet the question asks how remediation order is decided, which uses likelihood and impact.
- A
Asset age and user satisfaction
Why it fails: Asset age and user satisfaction do not quantify likelihood or impact, so they cannot order remediation work. They are tempting because ageing hardware correlates with failure and satisfaction signals service quality, but risk prioritisation requires likelihood and impact values, which these attributes do not provide.
- B
Likelihood and impact
Likelihood and impact together produce the risk score that drives prioritisation, letting the team rank findings objectively rather than by severity label alone. This directly satisfies the manager's question of which issue to fix first, since likelihood estimates exploitation probability and impact quantifies potential business loss.
- C
Vendor popularity and implementation speed
Why it fails: Vendor popularity and implementation speed say nothing about likelihood or business impact, so they cannot rank risks for remediation. They are tempting because procurement and rollout planning genuinely weigh vendor adoption and deployment timelines, but prioritisation requires likelihood and impact scores, not supplier metrics.
- D
Encryption algorithm and screen resolution
Why it fails: Encryption algorithm and screen resolution are technical and display attributes, not risk-ranking inputs; neither expresses likelihood or impact. They tempt because cryptographic strength matters in control selection and resolution in endpoint standards, yet the question asks how remediation order is decided, which uses likelihood and impact.