Q2
Single choice
A security analyst is reviewing a report that lists identified threats, their likelihood, impact, and whether
existing controls fully address them.
Which threat classification is being documented for items that still expose the application to limited risk?