Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ISC2 - CC - Chapter 1 - Module 2

Total questions: 35

Worksheet time: 18mins

Name
Class
Date
1.
What is impact in risk management?
a)
The probability of a risk occurring
b)
The potential consequences or severity of a risk
c)
The level of effort required for risk mitigation
d)
The financial value associated with a risk event
2.
The magnitude of the harm expected as result of the consequences of unauthorized disclosure, modification, destruction, or loss of information, is known as?
a)
Likelihood
b)
Threat
c)
Impact
d)
Vulnerability
3.
What is likelihood in risk management?
a)
The potential consequences or severity of a risk
b)
The probability of a risk occurring
c)
The level of effort required for risk mitigation
d)
The financial value associated with a risk event
4.
What is risk appetite in risk management?
a)
The willingness to take risks
b)
The complete avoidance of all risks
c)
The process of transferring risks to external parties
d)
The acceptance of all risks without any action
5.
Which of the following are the main categories of risk?
a)
Cyber attack risks and environmental risks
b)
Cyber attack risks and threat risks
c)
Vulnerability risks and environmental risks
d)
Cyber attack risks and automatic risks
6.
Why is risk management important in organizations?
a)
It eliminates all risks completely
b)
It ensures the confidentiality of sensitive information
c)
It helps organizations make informed decisions to mitigate potential risks
d)
It transfers all risks to external parties
7.
Which of the followings is usually used to represent risk?
a)
Threat actors and vulnerabilities
b)
Assets, vulnerabilities, and threats
c)
Likelihood and impact
d)
Probability and cause
8.
Risk can only exist when?
a)
Treat actors, assets and vulnerabilities are present
b)
Threat actors are able to identify targets
c)
Threats, assets and vulnerabilities are present
d)
Treat actors are able to find treat vectors
9.
What are assets in the context of risk management?
a)
The consequences or impacts of a risk event
b)
The potential threats that could exploit vulnerabilities
c)
The resources, information, or systems that have value to an organization
d)
The likelihood of a risk occurring
10.
In risk management concepts, a(n) _________ is something a security practitioner might need to protect?
a)
Vulnerability
b)
Asset
c)
Threat
d)
Likelihood
11.
Which of the following is an example of a tangible asset?
a)
Intellectual property
b)
Customer database
c)
Data center server
d)
Software application
12.
What are vulnerabilities in the context of risk management?
a)
The consequences or impacts of a risk event
b)
The potential threats that could exploit vulnerabilities
c)
The weaknesses or flaws in assets that can be exploited by threat actors
d)
The likelihood of a risk occurring
13.
Which of the following would probably not be considered a threat?
a)
A natural disaster
b)
A unintentional damage to the system caused by a user
c)
A laptop with sensitive data on it
d)
An external attacker trying to gain unauthorized access to the environment
14.
What is a threat actor in the context of risk management?
a)
The consequences or impacts of a risk event
b)
The entity that takes action exploit vulnerabilities
c)
The weaknesses or flaws in assets that can be exploited by threat actors
d)
The likelihood of a risk occurring
15.
Which of the following is an example of an insider?
a)
A malicious hacker attempting to breach a network
b)
A disgruntled employee leaking confidential information
c)
A natural disaster causing a power outage
d)
A software vulnerability allowing unauthorized access
16.
Which of the following threat actors is mainly motivated by other than financial gains?
a)
Formal non-political entities
b)
Formal political entities
c)
Intelligence
d)
Insiders
17.
Which of the following threat actors would be generally considered the most dangerous?
a)
Insiders
b)
Script kiddies
c)
Outside individuals
d)
Intelligence
18.
What is risk management?
a)
The process of eliminating all risks
b)
The process of identifying, assessing, and mitigating risks
c)
The process of accepting all risks without any mitigation
d)
The process of transferring risks to external parties
19.
What is the first step in the risk management process?
a)
Risk assessment
b)
Risk identification
c)
Risk mitigation
d)
Risk monitoring
20.
What is the correct sequential order of the main stages of the risk management process?
a)

Identification, treatment, and assessment

b)

Assessment, identification, and treatment

c)

Assessment, analysis, and mitigation

d)

Identification, assessment, and treatment

21.
What is the purpose of risk assessment in risk management?
a)
To identify potential vulnerabilities in an organization's assets
b)
To analyze the likelihood and impacts of various threats
c)
To transfer risks to external parties
d)
To implement security controls to mitigate risks
22.
Which of the following is a common risk assessment technique?
a)
Risk avoidance
b)
Risk acceptance
c)
Risk analysis
d)
Risk transference
23.
Which risk management activity involves prioritizing risks based on their potential impact and likelihood?
a)
Risk identification
b)
Risk analysis
c)
Risk mitigation
d)
Risk monitoring
24.
What is the purpose of a risk probability matrix?
a)
To assign numerical values to risks
b)
To assess risks based on their potential impact and likelihood
c)
To quantify risks using financial metrics
d)
To visualize the relationship between probability and impact of risks
25.
What is qualitative risk analysis?
a)
A process that assigns numerical values to risks
b)
A process that assesses risks based on their potential impact and likelihood
c)
A process that quantifies risks using financial metrics
d)
A process that transfers risks to external parties
26.
What is quantitative risk analysis?
a)
A process that assigns numerical values to risks
b)
A process that assesses risks based on their potential impact and likelihood
c)
A process that quantifies risks using financial metrics
d)
A process that transfers risks to external parties
27.
Which risk analysis approach provides more precise and quantitative results?
a)
Qualitative risk analysis
b)
Quantitative risk analysis
c)
Risk probability and impact assessment
d)
Risk response planning
28.
What is residual risk?
a)
The risk that remains after mitigation efforts
b)
The risk that is transferred to external parties
c)
The risk that is eliminated completely
d)
The risk that is accepted without any action
29.
Which of the following is NOT one of the four typical ways of managing risk?
a)
Avoid
b)
Accept
c)
Mitigate
d)
Conflate
30.
What is the role of risk mitigation in risk management?
a)
To eliminate all risks completely
b)
To minimize the potential impacts of identified risks
c)
To transfer all risks to external parties
d)
To accept all risks without any action
31.
Which of the following is an example of risk transference?
a)
Purchasing insurance
b)
Implementing security controls
c)
Conducting risk assessments
d)
Avoiding risky activities
32.
When an institution decides to stop operations until risk decreases, which risk treatment technique is being applied?
a)
Risk avoidance
b)
Risk acceptance
c)
Risk mitigation
d)
Risk transfer
33.
When an institution decides to hire an insurance company to deal with the risk, which risk treatment technique is being applied?
a)
Risk avoidance
b)
Risk acceptance
c)
Risk mitigation
d)
Risk transfer
34.
When an institution decides to continue operations despite the risk, which risk treatment technique is being applied?
a)
Risk avoidance
b)
Risk acceptance
c)
Risk mitigation
d)
Risk transfer
35.
When an institution decides to apply security controls to deal with the risk, which risk treatment technique is being applied?
a)
Risk avoidance
b)
Risk tolerance
c)
Risk mitigation
d)
Risk transfer