ITM-375 UPDATED ACTUAL Questions And Correct Answers
Terms in this set (68)
What is Risk? – The potential for loss when a threat exploits a vulnerability;
formula for risk often expressed as threat × vulnerability + potential loss.
What is a Threat – Anything with the potential to cause harm (like hackers, insiders, disasters)
What is commonly known for threats? you usually cannot eliminate threats, only reduce their impact or likelihood.
Vulnerability – A weakness in systems, processes, or controls that a threat can exploit;
A common conception for Vulnerabilities you can often reduce or fix vulnerabilities (patching, configuration, policies).
Threat/vulnerability pair – A specific combination of a particular threat and the particular vulnerability it can
exploit
An example of a threat and vulnerability "unpatched web server" + "remote exploit malware")
CVE Stands for – (Common Vulnerabilities and Exposures)
A CVE Is? A standardized public list of known cybersecurity vulnerabilities with unique IDs
(like CVE-2024-12345)
Mitre is also known as The organization that maintains the CVE list and other cybersecurity frameworks
and databases.
US-CERT – A U.S. government team that tracks, analyzes, and publishes alerts on
cybersecurity threats and vulnerabilities.
Exploit – The act, tool, or code that takes advantage of a vulnerability to cause harm or
gain unauthorized access ("exposing" the weakness).
Loss – The negative impact if a risk materializes, such as financial cost, data loss,
downtime, or reputational damage.
Cost (in risk) – The money, effort, and resources required to implement controls; you compare
this cost to the expected loss to decide if a control is worth it.
Threat-likelihood matrix – A chart that shows how likely a risk event is and how big the impact would be,
helping you prioritize which risks to handle first.
Probability – The two dimensions of the matrix: how often something might happen (likelihood)
impact how bad it is if it does happen
Terms in this set (68)
What is Risk? – The potential for loss when a threat exploits a vulnerability;
formula for risk often expressed as threat × vulnerability + potential loss.
What is a Threat – Anything with the potential to cause harm (like hackers, insiders, disasters)
What is commonly known for threats? you usually cannot eliminate threats, only reduce their impact or likelihood.
Vulnerability – A weakness in systems, processes, or controls that a threat can exploit;
A common conception for Vulnerabilities you can often reduce or fix vulnerabilities (patching, configuration, policies).
Threat/vulnerability pair – A specific combination of a particular threat and the particular vulnerability it can
exploit
An example of a threat and vulnerability "unpatched web server" + "remote exploit malware")
CVE Stands for – (Common Vulnerabilities and Exposures)
A CVE Is? A standardized public list of known cybersecurity vulnerabilities with unique IDs
(like CVE-2024-12345)
Mitre is also known as The organization that maintains the CVE list and other cybersecurity frameworks
and databases.
US-CERT – A U.S. government team that tracks, analyzes, and publishes alerts on
cybersecurity threats and vulnerabilities.
Exploit – The act, tool, or code that takes advantage of a vulnerability to cause harm or
gain unauthorized access ("exposing" the weakness).
Loss – The negative impact if a risk materializes, such as financial cost, data loss,
downtime, or reputational damage.
Cost (in risk) – The money, effort, and resources required to implement controls; you compare
this cost to the expected loss to decide if a control is worth it.
Threat-likelihood matrix – A chart that shows how likely a risk event is and how big the impact would be,
helping you prioritize which risks to handle first.
Probability – The two dimensions of the matrix: how often something might happen (likelihood)
impact how bad it is if it does happen