ITEC 433 Study Guide Exam 2026/2027 |
Complete Final Exam Prep | Practice
Questions, Answers & Detailed Review
When implementing risk management you have to achieve a balance between
what two areas?
a.business and safety
b.Business and security
c.threats and vulnerabilities
d.profit and loss - correct answer-Business and security
Phishing is a threat or vulnerability __________________ - correct answer-Threat
Which is not true about Cyber Risk Management?
a.Governance and framework are important for success
b.Cyber risk management is stragetic
c.Cyber is dynamic, a moving target
, d. Cyber risk is a technical issue, not a business issue. - correct answer-Cyber risk
is a technical issue, not a business issue
What is the definition of a risk? - correct answer-the likelihood that a loss will
occur
Cyber security risk has three key components forming the CIA triangle. Identify
each and define it. - correct answer-CIA stands for Confidentiality, Integrity, and
Availability.
Confidentiality is that only the appropriate/authorized individuals are allowed to
see the information.
Integrity is that the information shouldn't be modified or destroyed.
Availability means that the information should be available when needed.
Inherent risk should be always be higher or lower than Residual risk if controls are
in place
T or F - correct answer-False, needs to be higher
What is a vulnerability? - correct answer-A vulnerability is an opening or
weakness in the system, which if found can be exploited in order to do harm
What is a threat? - correct answer-Anything that has the potential to cause
danger.
Complete Final Exam Prep | Practice
Questions, Answers & Detailed Review
When implementing risk management you have to achieve a balance between
what two areas?
a.business and safety
b.Business and security
c.threats and vulnerabilities
d.profit and loss - correct answer-Business and security
Phishing is a threat or vulnerability __________________ - correct answer-Threat
Which is not true about Cyber Risk Management?
a.Governance and framework are important for success
b.Cyber risk management is stragetic
c.Cyber is dynamic, a moving target
, d. Cyber risk is a technical issue, not a business issue. - correct answer-Cyber risk
is a technical issue, not a business issue
What is the definition of a risk? - correct answer-the likelihood that a loss will
occur
Cyber security risk has three key components forming the CIA triangle. Identify
each and define it. - correct answer-CIA stands for Confidentiality, Integrity, and
Availability.
Confidentiality is that only the appropriate/authorized individuals are allowed to
see the information.
Integrity is that the information shouldn't be modified or destroyed.
Availability means that the information should be available when needed.
Inherent risk should be always be higher or lower than Residual risk if controls are
in place
T or F - correct answer-False, needs to be higher
What is a vulnerability? - correct answer-A vulnerability is an opening or
weakness in the system, which if found can be exploited in order to do harm
What is a threat? - correct answer-Anything that has the potential to cause
danger.