(ISC)2 Certified in Cybersecurity - Exam Prep with complete solutions
(ISC)2 Certified in Cybersecurity - Exam Prep with complete solutions Document specific requirements that a customer has about any aspect of a vendor's service performance. A) DLR B) Contract C) SLR D) NDA - Answer️️ -C) SLR (Service-Level Requirements) _________ identifies and triages risks. - Answer️️ -Risk Assessment _________ are external forces that jeopardize security. - Answer️️ -Threats _________ are methods used by attackers. - Answer️️ -Threat Vectors _________ are the combination of a threat and a vulnerability. - Answer️️ -Risks We rank risks by _________ and _________. - Answer️️ -Likelihood and impact _________ use subjective ratings to evaluate risk likelihood and impact. - Answer️️ - Qualitative Risk Assessment _________ use objective numeric ratings to evaluate risk likelihood and impact. - Answer️️ - Quantitative Risk Assessment _________ analyzes and implements possible responses to control risk. - Answer️️ -Risk Treatment _________ changes business practices to make a risk irrelevant. - Answer️️ -Risk Avoidance _________ reduces the likelihood or impact of a risk. - Answer️️ -Risk Mitigation An organization's _________ is the set of risks that it faces. - Answer️️ -Risk Profile _________ Initial Risk of an organization. - Answer️️ -Inherent Risk _________ Risk that remains in an organization after controls. - Answer️️ -Residual Risk _________ is the level of risk an organization is willing to accept. - Answer️️ -Risk Tolerance _________ reduce the likelihood or impact of a risk and help identify issues. - Answer️️ - Security Controls _________ stop a security issue from occurring. - Answer️️ -Preventive Control _________ identify security issues requiring investigation. - Answer️️ -Detective Control _________ remediate security issues that have occurred. - Answer️️ -Recovery Control Hardening == Preventative - Answer️️ -Virus == Detective Backups == Recovery - Answer️️ -For exam (Local and Technical Controls are the same) _________ use technology to achieve control objectives. - Answer️️ -Technical Controls _________ use processes to achieve control objectives. - Answer️️ -Administrative Controls _________ impact the physical world. - Answer️️ -Physical Controls _________ tracks specific device settings. - Answer️️ -Configuration Management _________ provide a configuration snapshot. - Answer️️ -Baselines (track changes) _________ assigns numbers to each version. - Answer️️ -Versioning _________ serve as important configuration artifacts. - Answer️️ -Diagrams _________ and _________ help ensure a stable operating environment. - Answer️️ -Change and Configuration Management Purchasing an insurance policy is an example of which risk management strategy? - Answer️️ -Risk Transference What two factors are used to evaluate a risk? - Answer️️ -Likelihood and Impact What term best describes making a snapshot of a system or application at a point in time for later comparison? - Answer️️ -Baselining What type of security control is designed to stop a security issue from occurring in the first place? - Answer️️ -Preventive What term describes risks that originate inside the organization? - Answer️️ -Internal What four items belong to the security policy framework? - Answer️️ -Policies, Standards, Guidelines, Procedu
Document information
- Uploaded on
- February 21, 2024
- Number of pages
- 79
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers