SSCP: Systems Security Certified Practitioner: Risk Management QUESTIONS WITH COMPLETE SOLUTIONS
Risk refers to what? correct answer: The probability of an incident occurring that can result in some negative impact Effective way to ensure zero risk? correct answer: None not engaging in the activity that introduces that risk Risk Register correct answer: Detailed document of compiled risks Output of risk assessment Why can sharing threat intelligence be complicated? correct answer: Legal Security Privacy How is the impact of a risk measured? correct answer: Through risk assessment Risk level correct answer: based on the overall impact the event would have on an organization's assets or business processes Quantitative risk assessment is based on what? correct answer: Monetary assessment identifies the impact Qualitative risk assessment base on what? correct answer: Expert opinion to identifies impact Vulnerabilities are defined as what? correct answer: Infrastructure Network System Weaknesses The vulnerabilities could be related to? correct answer: System Security Design Implementation Internal Controls Loss occurs when? correct answer: When a weakness is exploited by a threat What are come common vulnerabilities? correct answer: Insufficient antivirus protection Disgruntled employees Inadequate access controls Lack of change management measures Insufficient system hardening Single points of system failure Uneducated users Risk assessments do what? correct answer: examine risk within a set time period identify potential risks and mitigating measures
Document information
- Uploaded on
- March 4, 2023
- Number of pages
- 4
- Written in
- 2022/2023
- Type
- Exam (elaborations)
- Contains
- Questions & answers