Exam 2026|2027 Actual Complete Real Exam Questions
And Correct Answers (Verified Answers) Already
Graded A+ | Guaranteed Success! Newest Exam
| Just Released!!
Carl is a security professional preparing to perform a risk
assessment on database servers. He is reviewing the findings
of a previous risk assessment. He is trying to determine which
controls should be in place but were not implemented. Which of
the following is typically found in a risk assessment report and
would address Carl's needs? - ANSWER-Current status of
accepted recommendations
Carl is a security specialist. He is updating the organization's
hardware inventory in the asset management system. Which of
the following would be least helpful to record? - ANSWER-A
competitor's product
Companies use risk assessment strategies to differentiate
___________ from
_________. - ANSWER-severe risks,
minor risks
Email addresses or domains ______________ are
automatically marked as
spam. - ANSWER-on a
blacklist
,Hajar is a security professional for a government contractor.
Her company recently hired three new employees for a special
project, all of whom have a security clearance for Secret data.
Rather than granting the employees access to all files and
folders in the data repository, she is granting them access only
to
the data they need for the project. What principle is
Hajar following? -
ANSWER-Principle of need
to know
Hajar is a security specialist. Her organization has about 500
systems that must be tracked for inventory purposes. She is
preparing an email to her manager that describes the benefits
of including specific details about software in the inventory, as
well as the use of an automated asset management system.
Which of the following is not one of those benefits? - ANSWER-
The frequency of operating system upgrades will be reduced.
Hardening a server refers to:
A. expanding its attack surface.
B. a type of attack that removes the authorization to access a
company's systems from high-level employees in a
corporation.
C. the combination of all the steps that it takes to protect a
vulnerable system and make it more secure than the default
installation.
,D. a type of attack that deletes vital data from a server. -
ANSWER-the combination of all the steps that it takes to
protect a vulnerable system and make it more secure than
the default installation.
How can you determine the importance of a system? -
ANSWER-By how the
system is
used
In a quantitative risk assessment, what describes the loss
that will happen to
the asset as a result of a threat? - ANSWER-Exposure
factor (EF)
In a risk assessment, which of the following refers to how
responsibilities are
assigned? - ANSWER-Management
Structure
In a risk management plan, how should you complete the step
of describing the
procedures and schedules for
accomplishment?
A. Create an affinity diagram and a threat-likelihood-impact
matrix; assign the task to a stakeholder; and submit the official
schedule to management.
, B. Present stakeholders with a list of vulnerabilities that
need addressing and the steps involved with fixing each
vulnerability; ask them to assess how long it will take them to
address each of those vulnerabilities; and create an official
schedule for the stakeholders based on their estimated
timetable.
C. For any threat or vulnerability, recommend a solution that
attempts to mitigate associated risks; justify your
recommendation; list the tasks necessary for addressing the
vulnerability; and provide management with an estimate of how
long it will take to complete the recommendation. - ANSWER-
For any threat or vulnerability, recommend a solution that
attempts to mitigate associated risks; justify your
recommendation; list the tasks necessary for addressing the
vulnerability; and provide management with an estimate of how
long it will take to complete the recommendation.
In which of the following domains does the IT infrastructure
link to a wide area
network (WAN) and the
Internet?
A. WAN Domain
B. Systems/Applications Domain
C. LAN Domain
D. LAN-to-WAN Domain - ANSWER-LAN-to-WAN Domain
Isabella is a risk management specialist for her organization.
She is training Arturo, a new hire, on aspects of risk