INDIVIDUAL MANAGE YOUR RISK QHS EXAM
TEST PAPER 2026 COMPLETE RESPONSES
GRADED A+
◉ Control. Answer: Action or change put in place to reduce
weaknesses or potential losses. Also referred to as a
countermeasure.
◉ Disaster Recovery Plan (DRP). Answer: A plan used to recover a
system or systems after a disaster. Part of a business continuity plan.
◉ Risk. Answer: An uncertainty that may lead to a loss. Losses occur
when a threat exploits a vulnerability
◉ Risk Management. Answer: The practice of identifying, assessing,
controlling, and mitigating risks
◉ Risk Statement. Answer: A statement used to summarize risks.
These often use an "if/then" format
◉ Acceptable use policy. Answer: A policy that informs employees
what is considered acceptable use for IT systems and data.
, ◉ Advanced Encryption Standard (AES). Answer: The standard
defined by NIST for symmetric encryption
◉ Annual Loss Expectancy (ALE). Answer: Total expected loss from
a given risk for a year. Calculated by multiplying SLE × ARO
◉ Annual Rate of Occurrence (ARO). Answer: Number of times loss
from a given threat is expected to occur in a year.
◉ Audit. Answer: A check to see if an organization is following rules
and guidelines. A vulnerability assessment audit checks to see if
internal policies are followed.
◉ Audit Trail. Answer: A series of events recorded in one or more
logs. Audit trail events record who, what, where, and when.
◉ Availability. Answer: Ensuring that data or a service is available
when needed. In CIA Triad.
◉ Buffer Overflow. Answer: Commonly used against public facing
servers. Attackers in this attack send more or different data than is
expected.
TEST PAPER 2026 COMPLETE RESPONSES
GRADED A+
◉ Control. Answer: Action or change put in place to reduce
weaknesses or potential losses. Also referred to as a
countermeasure.
◉ Disaster Recovery Plan (DRP). Answer: A plan used to recover a
system or systems after a disaster. Part of a business continuity plan.
◉ Risk. Answer: An uncertainty that may lead to a loss. Losses occur
when a threat exploits a vulnerability
◉ Risk Management. Answer: The practice of identifying, assessing,
controlling, and mitigating risks
◉ Risk Statement. Answer: A statement used to summarize risks.
These often use an "if/then" format
◉ Acceptable use policy. Answer: A policy that informs employees
what is considered acceptable use for IT systems and data.
, ◉ Advanced Encryption Standard (AES). Answer: The standard
defined by NIST for symmetric encryption
◉ Annual Loss Expectancy (ALE). Answer: Total expected loss from
a given risk for a year. Calculated by multiplying SLE × ARO
◉ Annual Rate of Occurrence (ARO). Answer: Number of times loss
from a given threat is expected to occur in a year.
◉ Audit. Answer: A check to see if an organization is following rules
and guidelines. A vulnerability assessment audit checks to see if
internal policies are followed.
◉ Audit Trail. Answer: A series of events recorded in one or more
logs. Audit trail events record who, what, where, and when.
◉ Availability. Answer: Ensuring that data or a service is available
when needed. In CIA Triad.
◉ Buffer Overflow. Answer: Commonly used against public facing
servers. Attackers in this attack send more or different data than is
expected.