NEW
Font size
WorksheetsModule 1 Quiz 1 - Risk Management
Total questions: 15
Worksheet time: 8mins
A risk manager is planning a first-ever risk assessment in an organization. What is the best approach for ensuring success?
Interview personnel separately so that their responses can be compared
Select a framework that matches the organization’s control framework
Work with executive management to determine the correct scope
Do not inform executive management until the risk assessment has been completed
A security manager has completed a vulnerability scan and has identified numerous vulnerabilities in production servers. What is the best course of action?
Notify the production servers’ asset owners
Conduct a formal investigation
Place a single entry into the risk register
Put individual vulnerability entries into the risk register
The concept of security tasks in the context of a SaaS or IaaS environment is depicted in a
Discretionary control model
Mandatory control model
Monte Carlo risk model
Shared responsibility model
A security manager is developing a vision for the future state of a risk management program. Before she can develop the plan to achieve the vision, she must perform a:
Gap analysis
Risk analysis
Risk assessment
Threat assessment
All of the following are techniques to identify risks, except
Penetration tests
Threat modelling
Vulnerability assessment
Risk treatment
The main advantage of NIST standards versus ISO standards is:
NIST standards are considered global standards
NIST standards are not copyrighted
NIST standards are available without cost
NIST standards cost less to implement
Which of the following statements is true about compliance risk?
Compliance risk can be tolerated when fines cost less than controls
Compliance risk is just another risk that needs to be understood
Compliance risk can never be tolerated
Compliance risk can be tolerated when it is optional
Misconfigured firewalls, missing antivirus, and lack of staff training are examples of:
Risks
Threats
Vulnerabilities
Threat actors
A phishing attack, network scan, and social engineering are examples of:
Risks
Threats
Vulnerabilities
Threat actors
A security manager has been directed by executive management not to document a specific risk in the risk register. This course of action is known as:
Burying the risk
Transferring the risk
Accepting the risk
Ignoring the risk
A security manager is performing a risk assessment on a business application. The security manager has determined that security patches have not been installed for more than a year. This finding is known as a:
Probability
Threat
Vulnerability
Risk
A security manager is performing a risk assessment on a data centre. He has determined that it is possible for unauthorized personnel to enter the data centre through the loading dock door and shut off utility power to the building. This finding is known as a:
Probability
Threat
Vulnerability
Risk
Hacktivists, criminal organizations, and crackers are all known as:
Threat actors
Risks
Threats
Exploits
All of the following are core elements used in risk identification, except
Threats
Vulnerabilities
Asset value
Asset owner
What is usually the primary objective of risk management?
Fewer and less severe security incidents
No security incidents
Improved compliance
Fewer audit findings
