Fundamentals of Cyber Risk Management Exam 2023
In the Incident Response Life Cycle, which of the following phases would identifying precursors and indication be expected? - Answer- B. Detection and Analysis Establishing the context and providing common perspective on how organizations manage risk is the goal of: - Answer- B. Risk Framing A decision made based upon business knowledge, executive management directives, historical perspectives, business goals, and environmental factors is known as: - Answer- C. Judgmental valuation Which security principle is concerned with the unauthorized modification of important or sensitive information? - Answer- B. Integrity In relation to risk management, people, information, technology, and facilities are examples of: - Answer- A. Assets Which of the following is the set of security controls for an information system that is primarily implemented and executed by people? - Answer- A. Operational Controls Methods of response for managing risks are: - Answer- D. Accept, Transfer, Mitigate, Avoid The inputs (threat source motivation, threat capacity, nature of vulnerability, and current controls) will aid in generating output used in which step of the NIST SP risk assessment guidance? - Answer- D. Likelihood Determination Which OCTAVE process involves collecting information about important assets, security requirements, threats, current organizational strengths, and vulnerabilities from managers of selected operational areas? - Answer- A. Identify Operational Area Knowledge If the cost of controls to mitigate a risk exceeds the cost of loss the organization would incur if a threat is realized, the decision may be made to accept the risk. - Answer- A. TRUE The threat-source is motivated and capable, but controls are in place that may impede successful exercise of the vulnerability. Which likelihood rating does this describe? - Answer- B. Medium Simulating attack from a malicious source could be part of penetration testing. - Answer- A. TRUE Controls to support business continuity would include: - Answer- D. All of the above Which of the following strategies for managing risk is described as: eliminating the asset's exposure to risk, or elimination of the asset itself? - Answer- D. Avoid Which of the following data classifications is most likely to apply to an organization's marketing materials? - Answer- C. Public Cyber risk management solutions are typically done through which categories of security controls? - Answer- D. Technical, Physical, Administrative Which of the following security control class is for an information system and primarily implemented and executed by people? - Answer- B. Operational When considering baseline security controls, an organization would find guidance on categorizing systems, followed by identifying minimum security requirements for that system category, and finally the recommended
Document information
- Uploaded on
- June 5, 2023
- Number of pages
- 3
- Written in
- 2022/2023
- Type
- Exam (elaborations)
- Contains
- Questions & answers