Which of the following can be calculated using the values from an annualized rate of occurrence
multiplied by the values from a single loss expectancy?
A) cost benefit analysis
B) annualized loss expectancy
C) asset valuation
D) operational feasibility correct answers B
What is an indirect objective of a business impact analysis?
A) to evaluate the effectiveness of controls
B) to justify funding
C) to calculate MAOs
D) to identify an impact that can result from disruptions in a business correct answers B
An organization should implement as many controls as possible. T/F? correct answers F
A business impact analysis is intended to include all IT functions. T/F? correct answers F
The value of an assessment is only as valuable as the expertise of the experts. T/F? correct answers T
Some recovery point objectives require you to recover data up to a moment in time. T/F? correct answers
T
When should you perform a risk assessment?
A) when eliminating a threat
B) continuously
C) when mitigating a threat
D) periodically correct answers D
It is often useful to categorize an organization's environments by risk sensitivity and then go deeper into
the specific sensitive resources in each environment. T/F? correct answers T
,Which of the following is NOT an example of what type of document a risk assessor could request during
a risk assessment?
A) Asset Inventories
B) Previously considered IT Security Recommendations
C) Current Security Policies, Standards and Procedures
D) Previous Information Security Risk Assessments
E) Copy of the BIA correct answers B
When using the RIIOT method for data gathering, it is essential to inspect security controls prior to
interviewing key personnel in order to understand the systems that employees are operating and
potentially putting at risk. T/F? correct answers F
What is the key principal element of an information security risk assessment?
A) vulnerability
B) threat agent
C) asset
D) threat correct answers C
Objectives during the interview phase of the RIIOT technique include all the following except:
A) Measurement of security awareness among staff
C) Identification of vulnerabilities in the area of the interviewee's expertise
C) Confirmation of managerial involvement in risk assessment process
D) Confirmation of security procedure execution
E) Confirmation of threat identification, asset valuation and critical systems identification correct answers
C
The objective of the "inspect security controls" approach in the RIIOT technique is to present alternative
methods of potentially reducing risks to an organization. T/F? correct answers F
A threat event where loss materializes and/or where liability increases.
A) Threat Event
, B) Vulnerability Event
C) Loss Event
D) Primary Event
E) Risk Event correct answers C
According to the CIA triad, which of the following is a desirable characteristic for computer security?
A) transparency
B) accountability
C) availability
D) decoupling correct answers C
All companies face the same set of vulnerabilities. T/F? correct answers F
When risk is reduced to an acceptable level, the remaining risk is referred to as _________.
A) remaining risk
B) acceptable risk
C) low-impact risk
D) residual risk correct answers D
Uncertainty level indicates how valid data is. T/F? correct answers T
Asset valuation is NOT a major priority of risk management. T/F? correct answers F
CBA stands for Cost Benefit Authorization. T/F? correct answers F
What may occur if you do NOT include the scope of the RA when defining it?
A) attacks
B) missed deadlines
C) exploited threats
D) losses correct answers B