WorksheetsRisk Assessment and Risk Management
Total questions: 10
Worksheet time: 5mins
In cybersecurity, what does Risk Assessment specifically measure?
The number of threats in the system
The cost of implementing security
The combination of likelihood and impact of an attack
The number of vulnerabilities in the network
Which of the following is an example of a vulnerability?
Hackers launching a ransomware attack
Using outdated software without security patches
Cyber defense team monitoring logs
A phishing email sent to users
Which of these is a preventive control in risk management?
Security cameras
Backups of data
Firewalls and multi-factor authentication
Monitoring network traffic
In the detective stage of risk management, the goal is to:
Stop risks before they happen
Spot risks quickly when they happen
Fix problems after they happen
Delete user accounts permanently
What is the main principle of the Zero Trust model?
Trust everyone once they're inside the network
Verify only external users, not internal users
Never trust, always verify
Use passwords as the only form of protection
(Scenario) A student downloads a free game from an unknown website. The game secretly installs malware on their laptop. What is the threat in this case?
The student clicking download
The free game website
The malware that harms the laptop
The laptop's weak antivirus
(Scenario) A company has strong passwords, but employees often reuse the same password for multiple systems. What is the vulnerability?
Employees reusing the same password
Hackers sending phishing emails
The company installing firewalls
The IT team monitoring login attempts
Which of the following best shows a convenience vs security trade-off?
Using one simple password for all accounts
Encrypting sensitive files before sending them
Installing antivirus on all school computers
Separating student WiFi from admin WiFi
Why do nations struggle with cyber defense even though they use risk assessment + management?
They only focus on personal devices
The scale is massive and attackers are often other nations
Cybersecurity doesn't apply at the national level
Because Zero Trust cannot be used at that scale
(Scenario) Hackers gain access to the school WiFi and try to move into the admin system. Which Zero Trust feature would best stop them?
Using a single shared password for everyone
Allowing access once inside the WiFi network
Requiring multi-factor authentication for every access attempt
Letting students and teachers share the same login
