100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

CYBER SECURITY AND INFORMATION ASSURANCE QUESTIONS AND ANSWERS 100% CORRECT!

Rating
-
Sold
-
Pages
7
Grade
A+
Uploaded on
16-01-2026
Written in
2025/2026

Risk Assessment - ANSWER means "the process of identifying, estimating, and prioritizing information security risks." What does risk assessment include? - ANSWER *Identify threats *Estimate the likelihood of being targeted *Identify vulnerabilities *Estimate the impact/harm should a threat successfully exploit a vulnerability *Estimate the likelihood that the harm will occur *Estimate risk as a function of the degree of harm and the likelihood that it will occur Responding/Treating Risk - ANSWER Avoid Mitigate Transfer Accept Avoid (Risk) - ANSWER Discontinue risky practice (decommission insecure system or prohibit insecure conduct) Mitigate(Risk) - ANSWER Apply measures to reduce the level of risk (encryption, AV, access control) Transfer(Risk) - ANSWER Shift the impact to some other entity(cyber-insurance, contractual means such as indemnification clauses) Accept(Risk) - ANSWER Process by which managers agree to accept the risk (e.g., managers understand risk and the possible options for treating it, but decide to accept it) Controls - ANSWER Measures that we put in place to mitigate risk Administrative Control - ANSWER management of policy oriented Technical Control - ANSWER Software or hardware oriented Physical Control - ANSWER Physical items (other than computer hardware) used to secure assets Control Functions - ANSWER Deterrence Prevention Detective Compensating Corrective Recovery Monitoring Risk - ANSWER * seeing if chosen risk responses are actually implemented * determining if they are effective * tracking changes in risk environment that need to be fed back into new assessment * verifying compliance with legal, contractual, an

Show more Read less
Institution
CYBER SECURITY AND INFORMATION ASSURANCE
Course
CYBER SECURITY AND INFORMATION ASSURANCE









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
CYBER SECURITY AND INFORMATION ASSURANCE
Course
CYBER SECURITY AND INFORMATION ASSURANCE

Document information

Uploaded on
January 16, 2026
Number of pages
7
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

  • managing

Content preview

CYBER SECURITY AND INFORMATION
ASSURANCE QUESTIONS AND ANSWERS
100% CORRECT!

, Risk - ANSWER is the likelihood that a threat agent will exploit a vulnerability and the
associated impact

Managing Risk - ANSWER means identifying, assessing, prioritizing, and treating
(responding to) risk; monitoring the evolving situation, and continuing the process

Risk Assessment - ANSWER means "the process of identifying, estimating, and
prioritizing information security risks."

What does risk assessment include? - ANSWER *Identify threats
*Estimate the likelihood of being targeted
*Identify vulnerabilities
*Estimate the impact/harm should a threat successfully exploit a vulnerability
*Estimate the likelihood that the harm will occur
*Estimate risk as a function of the degree of harm and the likelihood that it will occur

Responding/Treating Risk - ANSWER Avoid
Mitigate
Transfer
Accept

Avoid (Risk) - ANSWER Discontinue risky practice
(decommission insecure system or prohibit insecure conduct)

Mitigate(Risk) - ANSWER Apply measures to reduce the level of risk (encryption, AV,
access control)

Transfer(Risk) - ANSWER Shift the impact to some other entity(cyber-insurance,
contractual means such as indemnification clauses)

Accept(Risk) - ANSWER Process by which managers agree to accept the risk (e.g.,
managers understand risk and the possible options for treating it, but decide to accept
it)

Controls - ANSWER Measures that we put in place to mitigate risk

Administrative Control - ANSWER management of policy oriented

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Luckyexams Howard Community College
View profile
Follow You need to be logged in order to follow users or courses
Sold
26
Member since
1 year
Number of followers
2
Documents
1833
Last sold
1 week ago

3.6

5 reviews

5
2
4
1
3
1
2
0
1
1

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions