SECURITY THREAT AND RISK (STR) Exam 2026-2027
BANK QUESTIONS WITH DETAILED VERIFIED
ANSWERS EXAM QUESTIONS WILL COME FROM
HERE (100% Latest Already Graded A+
QUESTION 1
In the context of information security, which of the following best
defines a "threat"?
A) A weakness in a system that can be exploited
B) The likelihood of a harmful event occurring
C) Any potential danger to an asset or system
D) The impact of a security breach
Answer: C
Explanation: A threat is any potential danger to an asset or system,
which could be a person, event, or circumstance that has the capacity to
cause harm. A weakness is a vulnerability (A), likelihood combined with
impact is risk (B), and impact is the consequence of a breach (D).
QUESTION 2
,2|Page
Risk is mathematically defined as:
A) Threat multiplied by Vulnerability
B) Asset Value divided by Likelihood
C) Likelihood multiplied by Impact
D) Vulnerability plus Threat
Answer: C
Explanation: Risk is the product of the probability (likelihood) of an
adverse event occurring and the magnitude of its negative impact.
While threat and vulnerability interplay, the standard formula is
Likelihood × Impact.
QUESTION 3
Which threat actor category is most likely to be motivated by political
ideology rather than financial gain?
A) Hacktivists
B) Cybercriminals
C) Insider threats
D) Script kiddies
Answer: A
Explanation: Hacktivists are motivated by political or social causes.
Cybercriminals are financially driven, insider threats can be varied, and
script kiddies are often motivated by notoriety or curiosity.
,3|Page
QUESTION 4
A zero-day vulnerability refers to:
A) A vulnerability that was patched on the same day it was discovered
B) A vulnerability unknown to the vendor with no available patch
C) A vulnerability that affects only legacy systems
D) A vulnerability with a CVSS score of 10.0
Answer: B
Explanation: A zero-day vulnerability is one that is unknown to the
software vendor and for which no patch exists. It does not refer to
patching timelines, legacy systems exclusively, or necessarily a CVSS
score of 10.
QUESTION 5
Which of the following is a primary component of a qualitative risk
analysis?
A) Monetary loss calculations
B) Annualized Loss Expectancy (ALE)
C) Scenario-based ranking of risks
D) Return on Investment (ROI) for controls
Answer: C
, 4|Page
Explanation: Qualitative risk analysis uses subjective judgments and
scenario-based rankings (e.g., High, Medium, Low) rather than precise
monetary values. ALE and ROI are quantitative.
QUESTION 6
The CIA triad stands for:
A) Confidentiality, Integrity, Availability
B) Confidentiality, Investigation, Authorization
C) Control, Identification, Authentication
D) Classification, Integrity, Access
Answer: A
Explanation: The foundational security model comprises Confidentiality
(secrecy), Integrity (accuracy and trustworthiness), and Availability
(accessibility when needed).
QUESTION 7
In risk management, "residual risk" is:
A) The risk that remains after implementing security controls
B) The risk that is transferred to a third party
C) The total inherent risk before any controls
D) The risk of not complying with regulations