Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 179 páginas
Examen

SECURITY THREAT AND RISK (STR) EXAMINATION 350 MULTIPLECHOICE QUESTIONS WITH ANSWERS AND RATIONALES

Document preview thumbnail
Vista previa 4 fuera de 179 páginas

Are you a security professional, risk analyst, or IT student preparing for a Security Threat and Risk (STR) certification or comprehensive final exam? Look no further. The SECURITY THREAT AND RISK (STR) EXAMINATION is your ultimate test bank and study guide, meticulously designed to simulate the actual exam and solidify your understanding of information security risk management, threat modeling, and vulnerability assessment. This isn't just another set of practice questions; it's a powerful learning system. Featuring 350 multiple-choice questions, this resource provides a rigorous review of all key subject areas, mirroring the format and difficulty of high-stakes security certification exams. Inside this updated 2025/2026 edition, you will master: Foundational Concepts: Understand the CIA Triad, risk formula (Risk = Threat × Vulnerability × Impact), risk appetite, risk tolerance, and the four risk response strategies (Avoid, Mitigate, Transfer, Accept). Risk Assessment Methodologies: Master NIST SP 800-30, OCTAVE, FAIR (quantitative risk analysis), DREAD, and probability-impact matrices for qualitative and quantitative risk assessment. Threat Modeling & STRIDE: Learn the STRIDE threat categorization model (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) and how it maps to the CIA Triad. Vulnerability Management: Explore vulnerability scanners, the Common Vulnerability Scoring System (CVSS), patch management, zero-day vulnerabilities, and the vulnerability management lifecycle. Risk Management Frameworks & Standards: Get to grips with ISO 27001, NIST Cybersecurity Framework (CSF), COBIT, ITIL, ISO 31000, and compliance regulations (GDPR, HIPAA, PCI DSS). Security Controls: Understand preventive, detective, corrective, and deterrent controls, along with AAA (Authentication, Authorization, Accounting), encryption, firewalls, IDS/IPS, and IAM. Emerging Threats & Trends: Cover ransomware, phishing (spear phishing, whaling, smishing, vishing), social engineering, insider threats, malware, DDoS attacks, zero trust architecture, and AI/quantum computing threats. Security Operations & Incident Response: Learn incident response phases (Preparation, Detection, Containment, Eradication, Recovery, Lessons Learned), SIEM, SOAR, XDR, and business continuity planning (BCP, DR, RTO, RPO). This essential test bank provides: Detailed Rationales: Every question is followed by a clear, concise, and in-depth explanation of why the correct answer is right and the distractors are wrong, reinforcing your learning and helping you apply the "why" to real-world security scenarios. Realistic Exam Simulation: Practice with questions that cover the full breadth of the security risk curriculum, helping you build the stamina and confidence you need for a high-stakes exam. Updated Content: Written for the 2025/2026 exam cycle, ensuring you are studying the most current frameworks, standards, and emerging threat landscapes. Proven Study Method: These questions are crafted to challenge your critical thinking and identify areas needing further review, acting as a "final exam" to gauge your readiness.

Vista previa del contenido

SECURITY THREAT AND RISK (STR)
EXAMINATION 350 MULTIPLECHOICE
QUESTIONS WITH ANSWERS AND RATIONALES



SECTION 1: FOUNDATIONAL CONCEPTS (Questions 1–50)


1. What is the primary purpose of information security risk assessment?
A) To eliminate all security risks completely
B) To identify, evaluate, and prioritize risks to organizational assets
C) To assign blame when security incidents occur
D) To ensure compliance with all regulations


Correct Answer: B


Rationale: Risk assessment identifies threats, vulnerabilities, and impacts to
determine which risks require mitigation. It does not aim to eliminate all risks
(impossible) nor assign blame. Compliance is a secondary benefit.




2. Which of the following best defines a "vulnerability" according to NIST SP
80030?
A) Any potential occurrence that could harm an organization

,B) A weakness in an information system that could be exploited by a threat
C) The likelihood that a threat will materialize
D) The monetary value of an asset at risk


Correct Answer: B


Rationale: NIST SP 80030 defines vulnerability as a flaw or weakness in
system security procedures, design, implementation, or internal controls that
could be exercised by a threat source.




3. Which statement accurately describes the relationship between threat,
vulnerability, and risk?
A) Risk = Threat × Vulnerability × Impact
B) Risk = Threat + Vulnerability
C) Risk = Vulnerability Threat
D) Risk = Impact ÷ Vulnerability


Correct Answer: A


Rationale: Risk is commonly expressed as the product of threat, vulnerability,
and potential impact. A threat exploits a vulnerability, resulting in risk to an
asset.

,4. What is the CIA Triad in information security?
A) Confidentiality, Integrity, Availability
B) Control, Investigation, Authorization
C) Classification, Identification, Authentication
D) Continuity, Insurance, Assurance


Correct Answer: A


Rationale: The CIA Triad—Confidentiality, Integrity, and Availability—
represents the three primary goals of information security.




5. Which of the following is NOT one of the three main objectives of
information security?
A) Confidentiality
B) Integrity
C) Accessibility
D) Availability


Correct Answer: C


Rationale: The three main objectives are Confidentiality, Integrity, and
Availability. "Accessibility" is not a standard security objective; availability
addresses accessibility of authorized users.

, 6. What is a "threat" in the context of security risk management?
A) A weakness in a system's security controls
B) Any potential event or action that could cause harm to an organization
C) The value of an asset that could be lost
D) A security control that prevents unauthorized access


Correct Answer: B


Rationale: A threat is any potential occurrence—malicious or nonmalicious—
that could exploit a vulnerability and cause harm to an organization.




7. Which risk response strategy aims to eliminate a threat entirely?
A) Mitigate
B) Transfer
C) Avoid
D) Accept


Correct Answer: C


Rationale: Risk avoidance eliminates the threat by discontinuing the activity
that creates the risk or implementing controls that remove the threat
altogether.

Información del documento

Subido en
3 de agosto de 2026
Número de páginas
179
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$22.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
PassPath
3.7
(12)
Vendido
79
Seguidores
2
Artículos
1278
Última venta
3 días hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes