1|Page
SECURITY THREAT AND RISK (STR) EXAMINATION
COMPLETE VERIFIED QUESTIONS AND DETAILED
SOLUTIONS LATEST UPDATE THIS YEAR JUST
RELEASED
Which management officer implements and manages all
aspects of security, including risk analysis, security
policies and procedures, training, and emerging
technologies?
A. CPO
B. CFO
C. CSO
D. CIO - Answer-Explanation: The chief security officer
(CSO) is the officer that leads any security effort and
reports directly to the chief executive officer (CEO).
The chief privacy officer (CPO) is the officer responsible
for private information and usually reports directly to the
CIO. - Answer-The chief financial officer (CFO) is the
officer responsible for all financial aspects of an
organization.
,2|Page
The CFO reports directly to the CEO and must also
provide financial data for the shareholders and
government entities. - Answer-The chief information officer
(CIO) is the officer responsible for all information systems
and technology used in the organization and reports
directly to the CEO or CFO.
Which threat modeling perspective profiles malicious
characteristics, skills, and motivation to exploit
vulnerabilities?
A. application-centric
B. asset-centric
C. attacker-centric
D. hostile-centric - Answer-C
Explanation: Attacker-centric threat modeling profiles an
attacker's characteristics, skills, and motivation to exploit
vulnerabilities.
Application-centric threat modeling uses application
architecture diagrams to analyze threats. - Answer-Asset-
centric threat modeling uses attack trees, attack graphs, or
,3|Page
displaying patterns to determine how an asset can be
attacked.
Which of the following is NOT a consideration for security
professionals during mergers and acquisitions?
A. new data types
B. new technology types
C. cost of the merger or acquisition
D. the other organization's security awareness training
program - Answer-C
Explanation: A security professional should not be
concerned with the cost of a merger or an acquisition.
A security professional should only be concerned with
issues that affect security and leave financial issues to
financial officers.
What is the first stage of the security program life cycle?
A. Plan and Organize
B. Implement
, 4|Page
C. Operate and Maintain
D. Monitor and Evaluate - Answer-A
Explanation: The four stages of the security program life
cycle, in order, are as follows:
1. Plan and Organization
2. Implement
3. Operate and Maintain
4. Monitor and Evaluate
Which term indicates the monetary impact of each threat
occurrence?
A. ARO
B. ALE
C. EF
D. SLE - Answer-D
SECURITY THREAT AND RISK (STR) EXAMINATION
COMPLETE VERIFIED QUESTIONS AND DETAILED
SOLUTIONS LATEST UPDATE THIS YEAR JUST
RELEASED
Which management officer implements and manages all
aspects of security, including risk analysis, security
policies and procedures, training, and emerging
technologies?
A. CPO
B. CFO
C. CSO
D. CIO - Answer-Explanation: The chief security officer
(CSO) is the officer that leads any security effort and
reports directly to the chief executive officer (CEO).
The chief privacy officer (CPO) is the officer responsible
for private information and usually reports directly to the
CIO. - Answer-The chief financial officer (CFO) is the
officer responsible for all financial aspects of an
organization.
,2|Page
The CFO reports directly to the CEO and must also
provide financial data for the shareholders and
government entities. - Answer-The chief information officer
(CIO) is the officer responsible for all information systems
and technology used in the organization and reports
directly to the CEO or CFO.
Which threat modeling perspective profiles malicious
characteristics, skills, and motivation to exploit
vulnerabilities?
A. application-centric
B. asset-centric
C. attacker-centric
D. hostile-centric - Answer-C
Explanation: Attacker-centric threat modeling profiles an
attacker's characteristics, skills, and motivation to exploit
vulnerabilities.
Application-centric threat modeling uses application
architecture diagrams to analyze threats. - Answer-Asset-
centric threat modeling uses attack trees, attack graphs, or
,3|Page
displaying patterns to determine how an asset can be
attacked.
Which of the following is NOT a consideration for security
professionals during mergers and acquisitions?
A. new data types
B. new technology types
C. cost of the merger or acquisition
D. the other organization's security awareness training
program - Answer-C
Explanation: A security professional should not be
concerned with the cost of a merger or an acquisition.
A security professional should only be concerned with
issues that affect security and leave financial issues to
financial officers.
What is the first stage of the security program life cycle?
A. Plan and Organize
B. Implement
, 4|Page
C. Operate and Maintain
D. Monitor and Evaluate - Answer-A
Explanation: The four stages of the security program life
cycle, in order, are as follows:
1. Plan and Organization
2. Implement
3. Operate and Maintain
4. Monitor and Evaluate
Which term indicates the monetary impact of each threat
occurrence?
A. ARO
B. ALE
C. EF
D. SLE - Answer-D