WorksheetsIAS FQ TOF 50
Total questions: 50
Worksheet time: 25mins
STRIDE identifies threats by categorizing attacker motivations.
True
False
DREAD measures threat severity using five scoring factors.
True
False
OCTAVE focuses more on technical vulnerabilities than organizational risks.
True
False
RMF’s “Monitor” step occurs after system authorization.
True
False
Spoofing refers to unauthorized data modification.
True
False
A vulnerability alone already causes risk even without threats.
True
False
Backups are considered preventive controls.
True
False
Impact refers to how likely an attack will occur.
True
False
Antivirus software is designed primarily as a preventive control.
True
False
Attack Trees visually show multiple possible attack paths.
True
False
MFA is an example of a corrective control.
True
False
Discoverability measures how easy it is to detect an attack after it occurs.
True
False
RMF requires selecting controls before implementing them.
True
False
Information disclosure involves modifying stored data.
True
False
Phishing emails represent vulnerabilities in an organization.
True
False
Assets are any resources requiring protection.
True
False
A failed login attempt is automatically a threat.
True
False
DREAD’s Affected Users factor considers the number of impacted individuals.
True
False
OCTAVE evaluates asset value during the assessment.
True
False
Preventive controls detect anomalies.
True
False
Tampering refers to altering data without authorization.
True
False
RMF’s “Authorize” step guarantees security forever.
True
False
Threats and vulnerabilities must both exist to produce risk.
True
False
Cost-benefit analysis ensures that only cheap controls are selected.
True
False
PASTA simulates possible attacker activities.
True
False
Attack Trees give details on financial impacts of risks.
True
False
Repudiation means denying involvement in an action.
True
False
DREAD’s Damage Potential measures how destructive a threat can be.
True
False
Monitoring logs is a detective control.
True
False
Risk identification includes locating possible weaknesses.
True
False
NIST RMF requires ongoing monitoring of controls.
True
False
Backups restore systems after incidents.
True
False
A threat cannot exist without vulnerabilities.
True
False
Attack Trees use a root node to represent the final attacker objective.
True
False
Impact refers to potential consequences of a threat.
True
False
User training is considered a detective control.
True
False
STRIDE is most often used for system design threat modeling.
True
False
The OCTAVE model is typically used by small home users.
True
False
Vulnerabilities always come from external attackers.
True
False
RMF requires implementing controls before assessing them.
True
False
Cost-benefit analysis measures if a control’s advantages exceed its total cost.
True
False
Spoofing includes pretending to be another user.
True
False
Discoverability measures how easy it is to find a weakness.
True
False
A risk with low impact can still be considered high priority.
True
False
STRIDE includes Denial of Service as one category.
True
False
OCTAVE only applies to physical security threats.
True
False
Detective controls help discover unusual or unauthorized activity.
True
False
Impact assessment happens before vulnerability identification.
True
False
An asset must always be a physical device.
True
False
Backups are essential for critical systems to minimize data loss.
True
False
