The internal LAN is always considered a trusted zone. correct answers False
All of the following are reasons to perform risk assessments except? correct answers It enables us to
determine which risk assessment framework we should be using
Two of the activities involved in risk management include identifying risks and assessing risks. Which of
the following activities is part of the risk identification process? correct answers Inventory and categorize
assets
Threat ___________ is a process used to identify possible threats on a system. correct answers modeling -
or - analysis
What is NOT a type of control? correct answers Private
What is a benefit of a quantitative Risk Analysis? correct answers provides a CBA
What is the first element to be considered when conducting a Risk Assessment? correct answers What are
the organization's assets
Many qualitative assessments must be represented in some quantitative form. correct answers True
What is NOT a step in risk management? correct answers eliminating all risks
All IT services and servers are equally critical. correct answers False
All vulnerabilities result in loss. correct answers False
A Risk rating calculation = correct answers likelihood of vulnerability x value of asset - % mitigated risks
+ uncertainty
Data consistency is NOT a challenge when creating any type of Risk Assessment. correct answers False
, According to the CIA triad, which of the following is a desirable characteristic for computer security?
correct answers Availability
The first part of a qualitative Risk Rating attempts to prioritize risk. The remaining parts the qualitative
Risk Rating evaluates the effectiveness of controls as related to the risk. correct answers True
A key step in managing risk is to first understand and manage the source. correct answers True
What are the valid options for addressing risk? correct answers Mitigate
Ignore
Accept
Transfer
An Risk Assessment team should focus both on critical areas and on what management might consider
important. correct answers True
Small organizations with fewer resources will need to separate Risk Assessment, but larger and better
equipped organizations have streamlined the process so that only one Risk Assessment is needed for all
their systems. correct answers False
Identify the true statement. correct answers Exploited vulnerabilities result in losses.
Objectives during the interview phase of the RIIOT technique include all the following except: correct
answers Confirmation of managerial involvement in risk assessment process
Typical data collectors include everything but, ____. correct answers Retreats
This will often map out critical process within an organization and if done properly will also identify
specific systems supporting those processes. correct answers BIA
According to Talabis, what is the most rigorous and most encompassing activity in the information
security risk assessment process? correct answers Data Collection