CYBR 7300 Final Exam Questions with Correct
Answers
Acceptance
risk treatment strategy that indicates the organization is willing to accept the current level of
residual risk. Organization makes a conscious decision to do nothing else to protect an
information asset from risk and to accept the outcome from any resulting exploitation
Annualized Loss Expectancy (ALE)
In a cost-benefit analysis, the product of the annualized rate of occurrence and single loss
expectancy.
Annualized Rate of Occurrence (ARO)
the expected frequency of an attack, expressed on a per year basis
Asset Valuation
The process of assigning financial value or worth to each information asset.
Avoidance
risk treatment strategy that attempts to eliminate or reduce any remaining uncontrolled risk
through the application of additional controls and safeguards in an effort to change the
likelihood of a successful attack on an information asset
Behavioral Feasibility
An examination of how well a particular solution fits within the organization's culture and the
extent to which users are expected to accept the solution.
cost avoidance
,The financial savings from using the defense risk control strategy to implement a control and
eliminate the financial ramifications of an incident.
Cost-Benefit Analysis (CBA)
Also known as an economic feasibility study, the formal assessment and presentation of the
economic expenditures needed for a particular security control, contrasted with its projected
value to the organization.
defense risk treatment strategy
The risk treatment strategy that attempts to eliminate or reduce any remaining uncontrolled
risk through the application of additional controls and safeguards in an effort to change the
likelihood of a successful attack on an information asset. Also known as the avoidance
strategy.
Delphi Technique
a decision-making method in which members of a panel of experts respond to questions and
to each other until reaching agreement on an issue
Exposure Factor (EF)
The potential percentage of loss to an asset if a threat is realized.
FAIR
factor analysis of information risk, risk management framework developed by Jack A Jones
that can help organizations understand, analyze, and measure information risk.
ISO 31000
,developed using the Australian/New Zealand standard AS/NZS 4360:2004 as a foundation.
Provides a structured methodology for evaluating threats to economic performance in an
organization
Microsoft Risk Management Approach
Microsoft Corp. also promotes a risk management approach
• Four phases in the MS InfoSec risk management process:
- Assessing risk
- Conducting decision support
- Implementing controls
- Measuring program effectiveness
Mitigation Risk Treatment Strategy
risk treatment strategy that attempts to reduce the impact of the loss caused by an incident,
disaster, or attach through effective contingency planning and preparation
NIST Risk Management Framework (RMF)
National Institute of Standards and Technology approach outlined by two documents 800-37
and 800-39. Describes a process that organizations can use to frame risk decisions, assess
risk, respond to risk, and monitor for ongoing effectiveness
OCTAVE Methods
Operationally Critical Threat, Asset, and Vulnerability Evaluation method is an InfoSec risk
evaluation methodology that allows organizations to balance the protection of critical info
assets against the costs of providing protective and detection controls
Operational Feasibility
, An examination of how well a particular solution fits within the organization's culture and the
extent to which users are expected to accept the solution, also known as behavioral feasibility
Organizational Feasibility
Examination of how well a particular solution fits within the organization's strategic planning
objectives and goals
Political Feasibility
Examination of how well a particular solution fits within the organization's political
environment, for example, the working relationship within the organization's communities of
interest or between the organization and its external environment
Qualitative Valuation
provides you with the ability to gain an in-depth understanding of a program or process. It
involves the "why" and the "how" and allows a deeper look at issues of interest and to
explore nuances.
Single Loss Expectancy (SLE)
In a cost benefit analysis, the calculated value associated with the most likely loss from an
attack. The SLE is the product of the asset's value and the exposure factor
Technical Feasibility
An examination of how well a particular solution is supportable given the organization's
current technological infrastructure and resources, which include hardware, software,
networking, and personnel.
Termination Risk Treatment Strategy
Answers
Acceptance
risk treatment strategy that indicates the organization is willing to accept the current level of
residual risk. Organization makes a conscious decision to do nothing else to protect an
information asset from risk and to accept the outcome from any resulting exploitation
Annualized Loss Expectancy (ALE)
In a cost-benefit analysis, the product of the annualized rate of occurrence and single loss
expectancy.
Annualized Rate of Occurrence (ARO)
the expected frequency of an attack, expressed on a per year basis
Asset Valuation
The process of assigning financial value or worth to each information asset.
Avoidance
risk treatment strategy that attempts to eliminate or reduce any remaining uncontrolled risk
through the application of additional controls and safeguards in an effort to change the
likelihood of a successful attack on an information asset
Behavioral Feasibility
An examination of how well a particular solution fits within the organization's culture and the
extent to which users are expected to accept the solution.
cost avoidance
,The financial savings from using the defense risk control strategy to implement a control and
eliminate the financial ramifications of an incident.
Cost-Benefit Analysis (CBA)
Also known as an economic feasibility study, the formal assessment and presentation of the
economic expenditures needed for a particular security control, contrasted with its projected
value to the organization.
defense risk treatment strategy
The risk treatment strategy that attempts to eliminate or reduce any remaining uncontrolled
risk through the application of additional controls and safeguards in an effort to change the
likelihood of a successful attack on an information asset. Also known as the avoidance
strategy.
Delphi Technique
a decision-making method in which members of a panel of experts respond to questions and
to each other until reaching agreement on an issue
Exposure Factor (EF)
The potential percentage of loss to an asset if a threat is realized.
FAIR
factor analysis of information risk, risk management framework developed by Jack A Jones
that can help organizations understand, analyze, and measure information risk.
ISO 31000
,developed using the Australian/New Zealand standard AS/NZS 4360:2004 as a foundation.
Provides a structured methodology for evaluating threats to economic performance in an
organization
Microsoft Risk Management Approach
Microsoft Corp. also promotes a risk management approach
• Four phases in the MS InfoSec risk management process:
- Assessing risk
- Conducting decision support
- Implementing controls
- Measuring program effectiveness
Mitigation Risk Treatment Strategy
risk treatment strategy that attempts to reduce the impact of the loss caused by an incident,
disaster, or attach through effective contingency planning and preparation
NIST Risk Management Framework (RMF)
National Institute of Standards and Technology approach outlined by two documents 800-37
and 800-39. Describes a process that organizations can use to frame risk decisions, assess
risk, respond to risk, and monitor for ongoing effectiveness
OCTAVE Methods
Operationally Critical Threat, Asset, and Vulnerability Evaluation method is an InfoSec risk
evaluation methodology that allows organizations to balance the protection of critical info
assets against the costs of providing protective and detection controls
Operational Feasibility
, An examination of how well a particular solution fits within the organization's culture and the
extent to which users are expected to accept the solution, also known as behavioral feasibility
Organizational Feasibility
Examination of how well a particular solution fits within the organization's strategic planning
objectives and goals
Political Feasibility
Examination of how well a particular solution fits within the organization's political
environment, for example, the working relationship within the organization's communities of
interest or between the organization and its external environment
Qualitative Valuation
provides you with the ability to gain an in-depth understanding of a program or process. It
involves the "why" and the "how" and allows a deeper look at issues of interest and to
explore nuances.
Single Loss Expectancy (SLE)
In a cost benefit analysis, the calculated value associated with the most likely loss from an
attack. The SLE is the product of the asset's value and the exposure factor
Technical Feasibility
An examination of how well a particular solution is supportable given the organization's
current technological infrastructure and resources, which include hardware, software,
networking, and personnel.
Termination Risk Treatment Strategy