Fundamentals of Cyber Risk Management questions and answers verified and updated.
Fundamentals of Cyber Risk Management questions and answers verified and updated. In the Incident Response Life Cycle, which of the following phases would identifying precursors and indication be expected? - correct answers.B. Detection and Analysis Establishing the context and providing common perspective on how organizations manage risk is the goal of: - correct answers.B. Risk Framing A decision made based upon business knowledge, executive management directives, historical perspectives, business goals, and environmental factors is known as: - correct answers.C. Judgmental valuation Which security principle is concerned with the unauthorized modification of important or sensitive information? - correct answers.B. Integrity In relation to risk management, people, information, technology, and facilities are examples of: - correct answers.A. Assets Which of the following is the set of security controls for an information system that is primarily implemented and executed by people? - correct answers.A. Operational Controls Methods of response for managing risks are: - correct answers.D. Accept, Transfer, Mitigate, Avoid The inputs (threat source motivation, threat capacity, nature of vulnerability, and current controls) will aid in generating output used in which step of the NIST SP risk assessment guidance? - correct answers.D. Likelihood Determination Which OCTAVE process involves collecting information about important assets, security requirements, threats, current organizational strengths, and vulnerabilities from managers of selected operational areas? - correct answers.A. Identify Operational Area Knowledge If the cost of controls to mitigate a risk exceeds the cost of loss the organization would incur if a threat is realized, the decision may be made to accept the risk. - correct answers.A. TRUE The threat-source is motivated and capable, but controls are in place that may impede successful exercise of the vulnerability. Which likelihood rating does this describe? - correct answers.B. Medium Simulating attack from a malicious source could be part of penetration testing. - correct answers.A. TRUE Controls to support business continuity would include: - correct answers.D. All of the above Which of the following strategies for managing risk is described as: eliminating the asset's exposure to risk, or elimination of the asset itself? - correct answers.D. Avoid Which of the following data classifications is most likely to apply to an organization's marketing materials? - correct answers.C. Public Cyber risk management solutions are typically done through which categories of security controls? - correct answers.D. Technical, Physical, Administrative Which of the following security control class is for an information system and primarily implemented and executed by people? - correct answers.B. Operational
Document information
- Uploaded on
- September 22, 2023
- Number of pages
- 4
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers