2026/2027 CYBER SECURITY RISK
MANAGEMENT EXAM PREPARATION | KEY
CONCEPTS, QUESTIONS & ANSWERS
Security incident - correct answer-· Any event that compromised the
confidentiality, integrity, or availability of an information asset.
· A violation or imminent threat of violation of computer security policies,
acceptable use policies, or standard security practices.
"Data" breach - correct answer-An incident that resulted in confirmed disclosure,
not just exposure, to an unauthorized party
Personally Identifiable Information (PII) - correct answer-Any information about
an individual maintained by an agency, including
(1) any information that can be used to distinguish or trace an individual's
identity; and
(2) any other information that is linked or linkable to an individual, such as
medical, educational, financial, and employment information.
Sensitive PII - correct answer-is Personally Identifiable Information, which if lost,
compromised, or disclosed without authorization could result in substantial harm,
embarrassment, inconvenience, or unfairness to an individual.
Data Breach Overview - Common Types - correct answer-Physical
, Electronic
Skimming
Physical - correct answer-Physical theft of documents or equipment containing
cardholder account data such as receipts, files, and computer systems.
Electronic - correct answer-Unauthorized access on a system or network
environment where customer data is hosted, processed, stored, or transmitted.
Skimming - correct answer-The capture and recording of magnetic stripe data on
the back of credit cards. This process uses an external device that is installed on a
merchant's point of sale systems to harvest customer data.
Risk Management Goal - correct answer-To maximize the output of the
organization in terms of services, products, revenue, etc., while minimizing the
chance for unexpected outcomes
Cyber Security "Rules" - correct answer-When considering mitigations, controls
and procedures to increase security, they should never be at the expense of
human safety.
Enterprise Risk Management (ERM) - correct answer-Agency wide approach to
addressing full spectrum of significant risks by considering the combined array of
risks as an interrelated portfolio, not as a silo.
Risk Types - correct answer-Aggregate Risk -
Inherent Risk -
Residual risk -
MANAGEMENT EXAM PREPARATION | KEY
CONCEPTS, QUESTIONS & ANSWERS
Security incident - correct answer-· Any event that compromised the
confidentiality, integrity, or availability of an information asset.
· A violation or imminent threat of violation of computer security policies,
acceptable use policies, or standard security practices.
"Data" breach - correct answer-An incident that resulted in confirmed disclosure,
not just exposure, to an unauthorized party
Personally Identifiable Information (PII) - correct answer-Any information about
an individual maintained by an agency, including
(1) any information that can be used to distinguish or trace an individual's
identity; and
(2) any other information that is linked or linkable to an individual, such as
medical, educational, financial, and employment information.
Sensitive PII - correct answer-is Personally Identifiable Information, which if lost,
compromised, or disclosed without authorization could result in substantial harm,
embarrassment, inconvenience, or unfairness to an individual.
Data Breach Overview - Common Types - correct answer-Physical
, Electronic
Skimming
Physical - correct answer-Physical theft of documents or equipment containing
cardholder account data such as receipts, files, and computer systems.
Electronic - correct answer-Unauthorized access on a system or network
environment where customer data is hosted, processed, stored, or transmitted.
Skimming - correct answer-The capture and recording of magnetic stripe data on
the back of credit cards. This process uses an external device that is installed on a
merchant's point of sale systems to harvest customer data.
Risk Management Goal - correct answer-To maximize the output of the
organization in terms of services, products, revenue, etc., while minimizing the
chance for unexpected outcomes
Cyber Security "Rules" - correct answer-When considering mitigations, controls
and procedures to increase security, they should never be at the expense of
human safety.
Enterprise Risk Management (ERM) - correct answer-Agency wide approach to
addressing full spectrum of significant risks by considering the combined array of
risks as an interrelated portfolio, not as a silo.
Risk Types - correct answer-Aggregate Risk -
Inherent Risk -
Residual risk -