EXAMINATION 350 MULTIPLECHOICE
QUESTIONS WITH ANSWERS AND RATIONALES
SECTION 1: FOUNDATIONAL CONCEPTS (Questions 1–50)
1. What is the primary purpose of information security risk assessment?
A) To eliminate all security risks completely
B) To identify, evaluate, and prioritize risks to organizational assets
C) To assign blame when security incidents occur
D) To ensure compliance with all regulations
Correct Answer: B
Rationale: Risk assessment identifies threats, vulnerabilities, and impacts to
determine which risks require mitigation. It does not aim to eliminate all risks
(impossible) nor assign blame. Compliance is a secondary benefit.
2. Which of the following best defines a "vulnerability" according to NIST SP
80030?
A) Any potential occurrence that could harm an organization
,B) A weakness in an information system that could be exploited by a threat
C) The likelihood that a threat will materialize
D) The monetary value of an asset at risk
Correct Answer: B
Rationale: NIST SP 80030 defines vulnerability as a flaw or weakness in
system security procedures, design, implementation, or internal controls that
could be exercised by a threat source.
3. Which statement accurately describes the relationship between threat,
vulnerability, and risk?
A) Risk = Threat × Vulnerability × Impact
B) Risk = Threat + Vulnerability
C) Risk = Vulnerability Threat
D) Risk = Impact ÷ Vulnerability
Correct Answer: A
Rationale: Risk is commonly expressed as the product of threat, vulnerability,
and potential impact. A threat exploits a vulnerability, resulting in risk to an
asset.
,4. What is the CIA Triad in information security?
A) Confidentiality, Integrity, Availability
B) Control, Investigation, Authorization
C) Classification, Identification, Authentication
D) Continuity, Insurance, Assurance
Correct Answer: A
Rationale: The CIA Triad—Confidentiality, Integrity, and Availability—
represents the three primary goals of information security.
5. Which of the following is NOT one of the three main objectives of
information security?
A) Confidentiality
B) Integrity
C) Accessibility
D) Availability
Correct Answer: C
Rationale: The three main objectives are Confidentiality, Integrity, and
Availability. "Accessibility" is not a standard security objective; availability
addresses accessibility of authorized users.
, 6. What is a "threat" in the context of security risk management?
A) A weakness in a system's security controls
B) Any potential event or action that could cause harm to an organization
C) The value of an asset that could be lost
D) A security control that prevents unauthorized access
Correct Answer: B
Rationale: A threat is any potential occurrence—malicious or nonmalicious—
that could exploit a vulnerability and cause harm to an organization.
7. Which risk response strategy aims to eliminate a threat entirely?
A) Mitigate
B) Transfer
C) Avoid
D) Accept
Correct Answer: C
Rationale: Risk avoidance eliminates the threat by discontinuing the activity
that creates the risk or implementing controls that remove the threat
altogether.