wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Lesson 5.1 InfoSec Risk Management Basics

Total questions: 28

Worksheet time: 21mins

Name
Class
Date
1.

What is Information Security Risk Management?

a)

The forecasting and evaluation of financial risks together with the identification of procedures to avoid or minimize their impact.

b)

It allows the organization to assess, identify, and modify its overall security posture.

c)

It enables security, operations, organizational leadership, and other personnel to collaborate and view the entire organization from an attacker's perspective.

d)

Both B and C

e)

Controlling the likelihood and impact of bad things involving information.

2.

What is a "threat"?

a)

An unpatched system.

b)

A person or thing likely to cause damage or danger.

c)

A virus on a device.

d)

A weakness that results in unwanted attacks.

e)

Both A and B

3.

What type of incident is a misconfiguration?

a)

A threat

b)

A vulnerability

c)

An exploit

d)

Both B and C

4.

What is type of incident is phishing?

a)

A threat

b)

A vulnerability

c)

An exploit

d)

A recreational activity

5.

What is a vulnerability?

a)

The quality of being vulnerable.

b)

The quality of state of being exposed to the possibility of being attacked or harmed, physically or emotionally

c)

A weakness or gap in control.

d)

All of the above.

6.

Explain Risk.

4 lines
7.

True or false. If there isn't a vulnerability, there isn't a risk.

a)

True

b)

False

8.

Explain why risk is relative.

4 lines
9.

According to NIST Risk Management Framework, how many steps are in the process?

a)

4

b)

5

c)

6

d)

7

10.

What are the steps involved in the NIST Risk Management Framework?

a)

1. Identify Risk

2. Assess Risk

3. Control Risk

4. Review Controls

b)

1. Identify Risks

2. Measure Risks

3. Examine Solutions

4. Implement Solution

5. Monitor Results

c)

1. Categorize Info Systems

2. Select Security Controls

3. Implement Security Controls

4. Assess Security Controls

5. Authorize Info Systems

6. Monitor Security Controls

d)

1. Identify

2. Analyze

3. Evaluate

4. Prioritize

5. Treat

6. Monitor

11.

If you could simplify the Risk Management Process, which three steps would be critical to include in the cycle?

a)

1. Assess

2. Decide

3. Implement

b)

1. Identify

2. Fix

3. Monitor

c)

1. Guess

2. Solve

3. Pray

d)

1. Assess

2. Fix

3. Monitor

12.

What types of risk assessments are there? Select all that apply.

a)

qualitative

b)

intuitive

c)

quantitative

d)

objective

13.

Is a qualitative risk assessment objective or subjective in nature?

a)

objective

b)

subjective

c)

Both

d)

Neither

14.

Which type of risk assessment requires more expertise but considered less credible?

a)

Qualitative

b)

Intuitive

c)

Quantitative

d)

Objective

15.

What type of risk assessment provides better comparison data, less subjectivity, and more definitive decision-making?

a)

Qualitative

b)

Intuitive

c)

Quantitative

d)

Objective

16.

What type of data is qualitative? Select all that apply

a)

Gender

b)

Income

c)

Social Class

d)

Marital Status

e)

Family size

17.

What type of data is quantitative? Select all that apply

a)

Percent of lecture attended

b)

Type of instruction

c)

Clinical Skills performed

d)

Method of treatment

e)

Number of errors

18.

Why is it important to identify the scope of the risk assessment?

a)

Makes sure you relate to the broadness of the assessment.

b)

Makes sure you account for all the controls.

c)

It is critical to putting risk into context.

d)

All of the above.

19.

What are the 3 controls needed in scope to make sure the enterprise has a comprehensive risk assessment?

a)

administrative, physical and external vulnerabilities

b)

internal, external, and physical threats/ vulnerabilities

c)

Executive, managerial, and information security areas

d)

administrative, physical, and technical threats/ vulnerabilities

20.

When choosing a risk assessment, what are the attributes to look for that make it a better option? Choose all that apply.

a)

Measureability

b)

Context

c)

Comparison

d)

Simplicity

e)

Objectivity

21.

Identify the three things that make measurability valid.

a)

Context

Objectivity

Clarity

b)

Relevance

Objectivity

Consistency

c)

Relevance

Subjectivity

Context

d)

Relevance

Objectivity

Context

22.

A risk without a decision is which risk decision?

a)

Mitigate

b)

Ignore

c)

Accept

d)

Avoid

e)

Transfer

23.

Which of this is not a viable risk decision?

a)

Mitigate

b)

Ignore

c)

Accept

d)

Transfer

e)

Avoid

24.

This risk is not acceptable to the organization and the decision is to share some or all the risk with someone else - usually a 3rd party.

a)

Mitigate

b)

Accept

c)

Ignore

d)

Transfer

e)

Avoid

25.

This risk is not acceptable to the organization and the decision is to stop doing whatever it is/was that led to the risk.

a)

Accept

b)

Avoid

c)

Ignore

d)

Transfer

e)

Mitigate

26.

This risk is acceptable to the organization as-is. There is no need for further action (just because a risk esixts does not mean we have to do something about it.)

a)

Accept

b)

Mitigate

c)

Ignore

d)

Transfer

e)

Avoid

27.

This risk is not acceptable to the organization as-is and must be reduced by reducing the vulnerability or reducing the threat.

a)

Accept

b)

Mitigate

c)

Avoid

d)

Ignore

e)

Transfer

28.

True or False. First decide which risks are acceptable and which are not, then decide what to do about it.

a)

True

b)

False