ISC2 SSCP: Risk Identification, Monitoring, and Analysis Test with all
Correct & 100% Verified Answers |Already Graded A+
1. Risk Assessment The identification, analysis, and management of risks relevant to the
preparation of financial statements that are fairly presented in conformity
with GAAP.
2. Threat External force jeopardizing security
3. Exam TIP: specific methods that threats use to exploit a vulnerability
Threat Vector
(Attack Vector)
4. Vulnerability Weaknesses in security controls
5. Risk combination of a vulnerability and a corresponding threat
6. Qualitative Uses subjective ratings to evaluate risk likelihood and impact
Risk
Assessment
7. Quantitative Uses objective numeric ratings to evaluate risk likelihood and impact
Risk
- performed on a single risk and asset pair
Assessment
8. Asset Value (AV) Estimated value in dollars of an asset
-original cost
-depreciated cost
-replacement cost
9. Exposure expected percentage of damage to an asset
Factor (EF)
10.
1/
22
, ISC2 SSCP: Risk Identification, Monitoring, and Analysis Test with all
Correct & 100% Verified Answers |Already Graded A+
Single-loss Ex- Expected dollar loss if a risk occurs one time
pectancy
(SLE)
* EF = SLE
$20m * 50% = $10m
11. Annualized
Rate of number of times a risk is expected to occur each year
Occurrence
(ARO)
12. Annualized
Loss expected dollar loss from a risk in any given year
Expectancy
(ALE) SLE * ARO = ALE
$10m * 0.01 = $100,000
13. EXAM TIP: Be
pre-
pared to work
through a
quanti-tative risk
assess-ment
calculation on
the exam
14. Mean Time Average time to nonrepairable component will last
to Failure
(MTTF)
average time gap between failurs of a repairable asset
15. Mean Time
be-tween
Failures
(MTBF)
16. Mean Time to Re- Average time required to return a repairable component to service
pair (MTTR)
17. Risk Manage- Process of systematically analyzing potential responses to each risk
ment or
Treat-ment and imple-menting strategies to control those risks appropriately.
2/
22
, ISC2 SSCP: Risk Identification, Monitoring, and Analysis Test with all
Correct & 100% Verified Answers |Already Graded A+
18. Risk Manage- -Risk avoidance
ment
Strategies -Risk transference
-Risk mitigation
-Risk acceptance
19. Risk Avoidance changes organizations business practices
e.g. avoid risk of flood by relocating the data center
20. Risk transference shifts the impact of a risk to another organization
e.g. transfer risk of flood by purchasing flood insurance
21. Risk Mitigation Reduces the likelihood or impact of the risk
e.g. mitigate risk of flood by installing flood control measures
22. Risk Acceptance Accepts the risk without taking further action
e.g. accepting risk of a flood
23. EXAM TIP: Ignor-
ing a risk is not the
same as ac-
cepting a risk.
Ig-noring a risk
is
a failure of risk
management
24. Risk Profile full set of risks facing an organization
25. Inherent Risk the probability that in the absence of internal controls, material errors or
frauds
could enter the accounting system used to develop financial statements
3/
22
Correct & 100% Verified Answers |Already Graded A+
1. Risk Assessment The identification, analysis, and management of risks relevant to the
preparation of financial statements that are fairly presented in conformity
with GAAP.
2. Threat External force jeopardizing security
3. Exam TIP: specific methods that threats use to exploit a vulnerability
Threat Vector
(Attack Vector)
4. Vulnerability Weaknesses in security controls
5. Risk combination of a vulnerability and a corresponding threat
6. Qualitative Uses subjective ratings to evaluate risk likelihood and impact
Risk
Assessment
7. Quantitative Uses objective numeric ratings to evaluate risk likelihood and impact
Risk
- performed on a single risk and asset pair
Assessment
8. Asset Value (AV) Estimated value in dollars of an asset
-original cost
-depreciated cost
-replacement cost
9. Exposure expected percentage of damage to an asset
Factor (EF)
10.
1/
22
, ISC2 SSCP: Risk Identification, Monitoring, and Analysis Test with all
Correct & 100% Verified Answers |Already Graded A+
Single-loss Ex- Expected dollar loss if a risk occurs one time
pectancy
(SLE)
* EF = SLE
$20m * 50% = $10m
11. Annualized
Rate of number of times a risk is expected to occur each year
Occurrence
(ARO)
12. Annualized
Loss expected dollar loss from a risk in any given year
Expectancy
(ALE) SLE * ARO = ALE
$10m * 0.01 = $100,000
13. EXAM TIP: Be
pre-
pared to work
through a
quanti-tative risk
assess-ment
calculation on
the exam
14. Mean Time Average time to nonrepairable component will last
to Failure
(MTTF)
average time gap between failurs of a repairable asset
15. Mean Time
be-tween
Failures
(MTBF)
16. Mean Time to Re- Average time required to return a repairable component to service
pair (MTTR)
17. Risk Manage- Process of systematically analyzing potential responses to each risk
ment or
Treat-ment and imple-menting strategies to control those risks appropriately.
2/
22
, ISC2 SSCP: Risk Identification, Monitoring, and Analysis Test with all
Correct & 100% Verified Answers |Already Graded A+
18. Risk Manage- -Risk avoidance
ment
Strategies -Risk transference
-Risk mitigation
-Risk acceptance
19. Risk Avoidance changes organizations business practices
e.g. avoid risk of flood by relocating the data center
20. Risk transference shifts the impact of a risk to another organization
e.g. transfer risk of flood by purchasing flood insurance
21. Risk Mitigation Reduces the likelihood or impact of the risk
e.g. mitigate risk of flood by installing flood control measures
22. Risk Acceptance Accepts the risk without taking further action
e.g. accepting risk of a flood
23. EXAM TIP: Ignor-
ing a risk is not the
same as ac-
cepting a risk.
Ig-noring a risk
is
a failure of risk
management
24. Risk Profile full set of risks facing an organization
25. Inherent Risk the probability that in the absence of internal controls, material errors or
frauds
could enter the accounting system used to develop financial statements
3/
22