Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 173 pages
Exam (elaborations)

Master the STR Exam: Your A+ Pass to Security Threat & Risk

Document preview thumbnail
Preview 4 out of 173 pages

Stop stressing and start succeeding! This comprehensive question bank is your ultimate key to conquering the Security Threat and Risk (STR) exam. Featuring 300+ meticulously crafted questions with detailed, verified answers, this guide covers everything from the CIA triad and threat actors to risk management frameworks and attack vectors. Why waste time with unreliable study materials? This is the exact bank of questions you need to achieve a top score on your exam.

Content preview

1|Page




SECURITY THREAT AND RISK (STR) Exam 2026-2027
BANK QUESTIONS WITH DETAILED VERIFIED
ANSWERS EXAM QUESTIONS WILL COME FROM
HERE (100% Latest Already Graded A+




QUESTION 1
In the context of information security, which of the following best
defines a "threat"?
A) A weakness in a system that can be exploited
B) The likelihood of a harmful event occurring
C) Any potential danger to an asset or system
D) The impact of a security breach


Answer: C
Explanation: A threat is any potential danger to an asset or system,
which could be a person, event, or circumstance that has the capacity to
cause harm. A weakness is a vulnerability (A), likelihood combined with
impact is risk (B), and impact is the consequence of a breach (D).


QUESTION 2

,2|Page


Risk is mathematically defined as:
A) Threat multiplied by Vulnerability
B) Asset Value divided by Likelihood
C) Likelihood multiplied by Impact
D) Vulnerability plus Threat


Answer: C
Explanation: Risk is the product of the probability (likelihood) of an
adverse event occurring and the magnitude of its negative impact.
While threat and vulnerability interplay, the standard formula is
Likelihood × Impact.


QUESTION 3
Which threat actor category is most likely to be motivated by political
ideology rather than financial gain?
A) Hacktivists
B) Cybercriminals
C) Insider threats
D) Script kiddies


Answer: A
Explanation: Hacktivists are motivated by political or social causes.
Cybercriminals are financially driven, insider threats can be varied, and
script kiddies are often motivated by notoriety or curiosity.

,3|Page




QUESTION 4
A zero-day vulnerability refers to:
A) A vulnerability that was patched on the same day it was discovered
B) A vulnerability unknown to the vendor with no available patch
C) A vulnerability that affects only legacy systems
D) A vulnerability with a CVSS score of 10.0


Answer: B
Explanation: A zero-day vulnerability is one that is unknown to the
software vendor and for which no patch exists. It does not refer to
patching timelines, legacy systems exclusively, or necessarily a CVSS
score of 10.


QUESTION 5
Which of the following is a primary component of a qualitative risk
analysis?
A) Monetary loss calculations
B) Annualized Loss Expectancy (ALE)
C) Scenario-based ranking of risks
D) Return on Investment (ROI) for controls


Answer: C

, 4|Page


Explanation: Qualitative risk analysis uses subjective judgments and
scenario-based rankings (e.g., High, Medium, Low) rather than precise
monetary values. ALE and ROI are quantitative.


QUESTION 6
The CIA triad stands for:
A) Confidentiality, Integrity, Availability
B) Confidentiality, Investigation, Authorization
C) Control, Identification, Authentication
D) Classification, Integrity, Access


Answer: A
Explanation: The foundational security model comprises Confidentiality
(secrecy), Integrity (accuracy and trustworthiness), and Availability
(accessibility when needed).


QUESTION 7
In risk management, "residual risk" is:
A) The risk that remains after implementing security controls
B) The risk that is transferred to a third party
C) The total inherent risk before any controls
D) The risk of not complying with regulations

Document information

Uploaded on
August 5, 2026
Number of pages
173
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$25.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
2
Followers
2
Items
1446
Last sold
1 month ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions