Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 50 pages
Exam (elaborations)

INFORMATION SECURITY RISK MANAGEMENT CERTIFICATION EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Document preview thumbnail
Preview 4 out of 50 pages

INFORMATION SECURITY RISK MANAGEMENT CERTIFICATION EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF INFORMATION SECURITY RISK MANAGEMENT CERTIFICATION EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Content preview

INFORMATION SECURITY RISK
MANAGEMENT CERTIFICATION EXAM
WITH QUESTIONS AND VERIFIED
ANSWERS, PLUS DETAILED
RATIONALES/EXPERT VERIFIED FOR
GUARANTEED PASS 2026/LATEST
UPDATE/INSTANT DOWNLOAD PDF
1. An organization is conducting an information security risk
assessment for a critical customer database. The database has a
replacement value of $500,000, but a compromise could also cause
regulatory penalties, customer notification costs, legal expenses, and
reputational damage. Which approach BEST represents a
comprehensive risk assessment?
A. Assess only the purchase price of the database server
B. Assess the asset's confidentiality, integrity, and availability
requirements and estimate potential business impact from relevant threat
scenarios
C. Calculate risk exclusively from the number of vulnerabilities detected
by a scanner
D. Determine risk solely from the organization's annual cybersecurity
budget
Answer: B
Rationale: A comprehensive information security risk assessment
considers the business value and security objectives of the asset, the
threats and vulnerabilities affecting it, and the consequences if
confidentiality, integrity, or availability is compromised. Purchase
price alone does not represent business impact, while vulnerability
counts and budget levels are insufficient by themselves to determine
risk.
1

,2. A security manager identifies a threat with an estimated annual
probability of 20%. If the expected loss from a successful occurrence
is $250,000, what is the estimated Annualized Loss Expectancy
(ALE)?
A. $20,000
B. $50,000
C. $125,000
D. $250,000
Answer: B
Rationale: Annualized Loss Expectancy is commonly calculated as
Annualized Rate of Occurrence multiplied by Single Loss Expectancy.
Therefore, $250,000 × 0.20 = $50,000. The calculation represents the
expected annualized financial exposure under the assumptions used in
the assessment.


3. During a risk assessment, an organization discovers that an
internet-facing application contains a critical vulnerability.
However, exploitation requires an attacker to possess privileged
credentials that are rarely issued. What should the risk analyst do?
A. Automatically classify the vulnerability as critical risk
B. Ignore the vulnerability because exploitation is difficult
C. Consider both the vulnerability severity and the likelihood and impact
of the realistic threat scenario
D. Classify the risk solely according to the CVSS score
Answer: C
Rationale: Vulnerability severity is only one component of risk. Risk
assessment should consider the likelihood of exploitation in the
organization's specific environment, existing controls, threat
2

,capability, exposure, and potential business impact. A high technical
severity does not automatically mean the highest organizational risk.


4. Which statement BEST distinguishes a threat from a
vulnerability?
A. A threat is a weakness, while a vulnerability is an attacker
B. A threat represents a potential cause of harm, while a vulnerability is
a weakness that can be exploited
C. A threat is always intentional, while a vulnerability is always
accidental
D. A threat is a security control, while a vulnerability is a risk response
Answer: B
Rationale: A threat is a potential event, actor, or circumstance capable
of causing harm. A vulnerability is a weakness that could be exploited
by a threat. Risk emerges when threats can exploit vulnerabilities and
produce adverse consequences.


5. A risk manager is developing a risk register. Which information
would provide the MOST useful basis for executive decision-
making?
A. Only the names of discovered vulnerabilities
B. Risk scenario, affected assets, likelihood, business impact, existing
controls, risk owner, treatment decision, and residual risk
C. Only the number of penetration tests completed
D. Only the names of security products installed
Answer: B
Rationale: A useful risk register connects technical observations to
business consequences and management decisions. Including

3

, ownership, treatment, existing controls, and residual risk allows
management to understand accountability and determine whether
remaining exposure is acceptable.


6. An organization decides to purchase cyber insurance for a
particular risk instead of implementing additional security controls.
Which risk treatment strategy is this?
A. Risk avoidance
B. Risk modification
C. Risk transfer
D. Risk acceptance
Answer: C
Rationale: Risk transfer shifts some or all financial consequences of a
risk to another party, commonly through insurance or contractual
arrangements. The underlying threat does not necessarily disappear;
rather, financial responsibility for certain consequences is transferred.


7. A company decides to discontinue an internet-facing service
because its risk cannot be reduced to an acceptable level at a
reasonable cost. Which treatment strategy is being used?
A. Acceptance
B. Avoidance
C. Transfer
D. Monitoring
Answer: B
Rationale: Risk avoidance eliminates the activity, process, technology,
or condition that creates the risk. Discontinuing the service removes
the associated exposure rather than merely reducing or transferring it.

4

Document information

Uploaded on
August 28, 2026
Number of pages
50
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$25.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
profwhite
4.3
(20)
Sold
120
Followers
76
Items
4660
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions