Skip to main content
RelixQ
Menu
Course outline

The four variables

Evidence, confidence, and what 'unknown' means

The fourth variable: how confident the evidence is behind the other three answers, and how to treat what is genuinely unknown.

4 min read

What you'll be able to do

  • Explain why evidence confidence is treated as its own variable rather than folded into the others.
  • Distinguish a confirmed answer from an inferred one and from a genuinely unknown one.
  • State the safer default when confidence is low.

The first three variables each produced an answer: a lifetime, a harvestability judgment, a protecting mechanism. The fourth variable asks how much to trust each of those answers. A confirmed observation, a reasonable inference, and a guess are not the same thing, even when they happen to point to the same conclusion.

  • Confirmed — observed directly: a captured handshake trace, a verified backup retention policy, a data classification signed off by the data owner.
  • Inferred — reasoned from adjacent evidence: a service is assumed to use its platform default TLS configuration because no override was found in its configuration.
  • Unknown — no evidence either way. This is a legitimate answer, not a gap to paper over with an assumption.

This is also why a Mosca-style verdict, covered next, should always be dated and labeled with its confidence level rather than presented as settled fact. Confidence can change — a configuration gets confirmed, a vendor answers a questionnaire — without anything about the underlying data changing at all.

RelixQ's QAST scores exposure across exactly these four variables — data confidentiality lifetime, harvestability, the reachability of the protecting cryptography, and evidence confidence — for the same reason this course treats them separately: collapsing them into one number too early hides which one is actually driving the result.

With all four variables defined, the next module turns them into a decision: when does a given exposure become urgent enough to act on.

Knowledge check

A security team cannot determine whether a legacy internal service negotiates hybrid or classical-only key exchange, because the vendor has not answered the question and no packet capture exists.

What is the defensible way to record this variable until better evidence arrives?

Marking a lesson complete only updates this browser.