wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Module 1 Quiz 1 - Risk Management

Total questions: 15

Worksheet time: 8mins

Name
Class
Date
1.

A risk manager is planning a first-ever risk assessment in an organization. What is the best approach for ensuring success?

a)

Interview personnel separately so that their responses can be compared

b)

Select a framework that matches the organization’s control framework

c)

Work with executive management to determine the correct scope

d)

Do not inform executive management until the risk assessment has been completed

2.

A security manager has completed a vulnerability scan and has identified numerous vulnerabilities in production servers. What is the best course of action?

a)

Notify the production servers’ asset owners

b)

Conduct a formal investigation

c)

Place a single entry into the risk register

d)

Put individual vulnerability entries into the risk register

3.

The concept of security tasks in the context of a SaaS or IaaS environment is depicted in a

a)

Discretionary control model

b)

Mandatory control model

c)

Monte Carlo risk model

d)

Shared responsibility model

4.

A security manager is developing a vision for the future state of a risk management program. Before she can develop the plan to achieve the vision, she must perform a:

a)

Gap analysis

b)

Risk analysis

c)

Risk assessment

d)

Threat assessment

5.

All of the following are techniques to identify risks, except

a)

Penetration tests

b)

Threat modelling

c)

Vulnerability assessment

d)

Risk treatment

6.

The main advantage of NIST standards versus ISO standards is:

a)

NIST standards are considered global standards

b)

NIST standards are not copyrighted

c)

NIST standards are available without cost

d)

NIST standards cost less to implement

7.

Which of the following statements is true about compliance risk?

a)

Compliance risk can be tolerated when fines cost less than controls

b)

Compliance risk is just another risk that needs to be understood

c)

Compliance risk can never be tolerated

d)

Compliance risk can be tolerated when it is optional

8.

Misconfigured firewalls, missing antivirus, and lack of staff training are examples of:

a)

Risks

b)

Threats

c)

Vulnerabilities

d)

Threat actors

9.

A phishing attack, network scan, and social engineering are examples of:

a)

Risks

b)

Threats

c)

Vulnerabilities

d)

Threat actors

10.

A security manager has been directed by executive management not to document a specific risk in the risk register. This course of action is known as:

a)

Burying the risk

b)

Transferring the risk

c)

Accepting the risk

d)

Ignoring the risk

11.

A security manager is performing a risk assessment on a business application. The security manager has determined that security patches have not been installed for more than a year. This finding is known as a:

a)

Probability

b)

Threat

c)

Vulnerability

d)

Risk

12.

A security manager is performing a risk assessment on a data centre. He has determined that it is possible for unauthorized personnel to enter the data centre through the loading dock door and shut off utility power to the building. This finding is known as a:

a)

Probability

b)

Threat

c)

Vulnerability

d)

Risk

13.

Hacktivists, criminal organizations, and crackers are all known as:

a)

Threat actors

b)

Risks

c)

Threats

d)

Exploits

14.

All of the following are core elements used in risk identification, except

a)

Threats

b)

Vulnerabilities

c)

Asset value

d)

Asset owner

15.

What is usually the primary objective of risk management?

a)

Fewer and less severe security incidents

b)

No security incidents

c)

Improved compliance

d)

Fewer audit findings