answers verified to pass 2026/2027
A(n) _________ is the likelihood that something unexpected is going to occur.
A) risk
B) threat
C) exploit
D) vulnerability - correct answer ✔A
Companies use risk assessment strategies to differentiate ___________ from _________.
A) vulnerabilities, weaknesses
B) vulnerabilities, threats
C) risks, threats
D) severe risks, minor risks - correct answer ✔D
Which of the following is not an example of an intangible value?
A) Future lost revenue
B) Cost of gaining a consumer
C) Software application
D) Customer influence - correct answer ✔C
Which of the following is often the weakest link in IT security?
A) People
B) Use of passphrases
C) Physical security
,D) Use of computer firewalls - correct answer ✔A
A new company does not have a lot of revenue for the first year. Installing antivirus software for all the
company's computers would be very costly, so the owners decide to forgo purchasing antivirus software
for the first year of the business. In what domain of a typical IT infrastructure is a vulnerability created?
A) Workstation Domain
B) LAN-to-WAN Domain
C) WAN Domain
D) Remote Access Domain - correct answer ✔A
In which of the following domains does the IT infrastructure link to a wide area network (WAN) and the
Internet?
A) WAN Domain
B) Systems/Applications Domain
C) LAN Domain
D) LAN-to-WAN Domain - correct answer ✔D
A ______ to an asset occurs only when an attacker can exploit a vulnerability.
A) threat
B) loss
C) mitigation
D) risk - correct answer ✔B
What are the elements of the security triad?
A) Confidence, intelligence, and assessment
B) Cooperation, installation, and acquisition
C) Confidentiality, integrity, and availability
, D) Coordination, implementation, and authorization - correct answer ✔C
Which of the following statement is true?
A) Exploited vulnerabilities result in losses.
B) All vulnerabilities result in losses.
C) Vulnerability is a synonym for loss.
D) The method used to take advantage of a vulnerability is known as a threat. - correct answer ✔A
What is the practice of identifying, assessing, controlling, and mitigating risks?
A) Social engineering
B) Risk management
C) Risk mitigation
D) Vulnerability scanning - correct answer ✔B
Isabella works as a risk specialist for her company. She wants to determine which risks should be
managed and which should not by applying a test to each risk. Risks that don't meet the test are
accepted. What type of test does she apply?
A) Control test
B) Vulnerability test
C) Reasonableness test
D) Cost assessment - correct answer ✔C
Which of the following statements is not true of cost-benefit analysis?
A) Organizations should never spend more on controls than the value of the asset.
B) The amount spent on controls should be proportional to the risk, which is known as the principle of
proportionality.