WorksheetsCengage 15
Total questions: 20
Worksheet time: 10mins
Which of the following threats would be classified as the actions of a hacktivist?
External threat
Internal threat
Environmental threat
Compliance threat
Which of these is NOT a response to risk?
Mitigate
Accept
Resist
Avoid
Which of the following is NOT a threat classification category?
Compliance
Financial
Tactical
Strategic
In which of the following threat classifications would a power blackout be classified?
Operational
Managerial
Technical
Strategic
Which of the following approaches to risk calculation typically assigns a numeric value (1–10) or label (High, Medium, or Low) to represent a risk?
Quantitative
Qualitative
Rule based
Policy based
What is a list of potential threats and associated risks called?
Risk assessment
Risk matrix
Risk register
Risk portfolio
Giovanni is completing a report on risks. To which risk option would he classify the action that the organization has decided not to construct a new data center because it would be located in an earthquake zone?
Transfer
Avoid
Reject
Prevent
Aristide is explaining to a coworker the new cybersecurity asset management (CAM) system. Which of the following would he NOT say about a CAM?
It is a relatively new process that combines asset management with information security.
It can identify assets on a continuous and real-time basis.
It can use vulnerability scanners.
It is designed to replace asset management.
Emiliano needs to determine the expected monetary loss every time a risk occurs. Which formula will he use?
AV
SLE
ARO
ALE
Enzo is reviewing asset tracking for a certification exam. Which of the following is NOT true about asset tracking?
Asset tracking can be used to determine when assets should be upgraded, replaced, or disposed.
Asset tracking can help determine what assets add value.
Asset tracking is part of an asset management system.
Asset tracking traces the location of intangible assets.
Which of the following is a listing of assets by a seller of those assets?
Asset enumeration
Asset inventory
Asset counting
Asset verification
Which of the following is NOT a legally enforceable agreement but is still more formal than an unwritten agreement?
BPA
SLA
MOU
AMS
Angelo has received a document that is part of a contract that describes the work requirements for a specific project. What type of document is this?
EOA
BPP
SOW
EOS
Which of the following uses scientific tools to determine the amount of variation that is added to a process?
XRS
MSA
RAR
PDP
Which of the following risk management strategies utilizes cybersecurity insurance?
Accept
Transfer
Mitigate
Change
Which of the following is NOT a third-party risk?
On-boarding
Social media network sharing
Risk awareness
Network assignment
Sergio has been asked to provide historical data for calculating the likelihood of a risk. Which of the following data sets would he NOT submit?
Network packet analysis
Law enforcement data
Insurance company data
Data from computer incident monitoring organizations
Which of the following is used to minimize biases and prejudices regarding analyzing risks?
RCSA
RCA
SCRA
DOS
Which of the following is NOT a standard operating procedure that can impact information security?
Change in ownership or stakeholders
Implement impact analysis or test results
Execute backout plan or maintenance window
Change allow lists/deny lists
Gabe is creating a report for his supervisor Cora that outlines the total risk that the organization can bear in a given risk profile. Which of the following terms would Gabe be using?
Risk tolerance
Risk appetite
Risk expansion
Risk acceptance
