CASP (questions with complete
solutions ) A+ rated
Scope of Protection - correct answer ✔✔The protection provided by the European Union regulations,
which does not extend once you move outside its walls.
Facets of Risk Management - correct answer ✔✔Include Risk Assessment, Risk Measurement, Risk
Handling, Risk Tracking, Risk Management Lifecycle, and Risk Considerations.
Risk - correct answer ✔✔The probability that a threat will be realized and involves a continual balancing
act of a vulnerability against a threat.
Vulnerabilities - correct answer ✔✔Weaknesses in system design or implementation, such as software
bugs, misconfigured software, improperly protected network devices, and lacking physical security,
which can increase risk.
Threat - correct answer ✔✔Anything that could cause harm, loss, damage, or compromise to
information technology systems.
Relationship between Risk, Threats, and Vulnerabilities - correct answer ✔✔Risk exists in the
intersection area between threats and vulnerabilities, highlighting the importance of managing both to
minimize potential harm.
Risk Management - correct answer ✔✔Helps organizations minimize the likelihood of negative outcomes
and achieve desired outcomes while also putting controls in place to reduce risk to an acceptable level.
Risk Management Lifecycle - correct answer ✔✔Helps organizations identify and manage different risks,
implementing controls to bring the level of risk down to an acceptable level.
Examples of Vulnerabilities - correct answer ✔✔Include software bugs, misconfigured software,
improperly protected network devices, and lacking physical security.
,Risk Management and Legal Troubles - correct answer ✔✔By identifying and mitigating risks, risk
management can help organizations avoid situations that may lead to legal issues.
Purpose of Risk Management - correct answer ✔✔Ensures that we are able to establish trust and
mitigate liability.
Risk Identification - correct answer ✔✔Considers all types of risks or uncertainties that may impact
achieving a set of objectives.
NIST Framework - correct answer ✔✔Provides a framework aimed at establishing a strategic risk
management framework supported by key stakeholders.
Respond Phase - correct answer ✔✔Focuses on the mitigations put into place to lower the assessed risk.
Control - correct answer ✔✔Refers to the mitigations put into place to lower risk.
Categories of Control - correct answer ✔✔The 7 categories are People, Process, Technology, Protect,
Detect, Respond, and Restore/Recover.
Monitor Category - correct answer ✔✔Evaluates the effectiveness of risk response measures and
identifies changes that could affect risk management.
Formal Risk Analysis - correct answer ✔✔Conducted to determine risk levels and inform decision-
making.
Qualitative Risk Analysis - correct answer ✔✔Uses intuition, experience, and best practices to assign
non-numeric values to a given risk.
Methods in Qualitative Risk Analysis - correct answer ✔✔Include brainstorming sessions, focus groups,
and surveys.
,Delphi Method - correct answer ✔✔Involves estimating the likelihood of events occurring by gathering
expert opinions to assess proposed impact severity, loss potential, and likelihood of occurrence.
Quantitative Risk Analysis - correct answer ✔✔Uses numeric and monetary values for all parts of the risk
analysis to provide a measurable assessment of risks.
Equations in Risk Analysis - correct answer ✔✔Used to determine total and residual risk, providing a cost
directly associated with those risks.
Inherent Risk - correct answer ✔✔The level of risk identified before any mitigating actions are applied to
reduce its impact or likelihood.
Residual Risk - correct answer ✔✔The risk that remains after mitigation measures and security controls
have been applied.
Risk Exception - correct answer ✔✔Any risk created due to an exemption being granted or a failure to
comply with corporate policy.
Avoiding Risk Exceptions - correct answer ✔✔Organizations can avoid risk exceptions by implementing
strict compliance with corporate policies and not granting unnecessary exemptions.
Risk Avoidance - correct answer ✔✔A strategy that involves stopping a risky activity or choosing a less
risky alternative to eliminate hazards and exposures.
Risk Transfer - correct answer ✔✔Involves shifting the risk to another party, often through insurance or
outsourcing, to mitigate potential negative impacts.
Risk Mitigation - correct answer ✔✔A strategy that seeks to minimize the risk to an acceptable level that
an organization can accept.
Risk Acceptance - correct answer ✔✔A strategy that seeks to accept the current level of risk and the
costs associated with it.
, Risk Appetite - correct answer ✔✔Refers to the amount of risk that an organization is willing to accept in
pursuit of its objectives, also known as risk attitude or risk tolerance.
Risk Tracking - correct answer ✔✔Involves systematically tracking and evaluating the performance of risk
mitigation actions against established metrics throughout the lifecycle of an identified risk.
Risk Register - correct answer ✔✔A tool used to identify potential risks in a system or organization.
Components of a Risk Register - correct answer ✔✔Should include: Risk identified, Description, Level,
Likelihood, Owner, Mitigation measures implemented, and Residual level.
Owner in Risk Management - correct answer ✔✔The person responsible for managing the threats and
vulnerabilities that might exploit a specific risk.
Key Performance Indicators (KPIs) - correct answer ✔✔Metrics and numbers used to gauge and measure
different aspects of performance within an organization.
Scalability - correct answer ✔✔The ability of a system or process to handle a growing amount of work or
its potential to accommodate growth.
Reliability - correct answer ✔✔The measurement of the probability that the system will meet certain
performance standards and yield the correct output for a specific time.
Availability - correct answer ✔✔Refers to the percentage of time that the infrastructure, system, or
solution is operational under normal circumstances.
Key Risk Indicators (KRIs) - correct answer ✔✔Used to measure risk rather than system performance.
Risk Assessment - correct answer ✔✔A tool used during risk management to identify vulnerabilities and
assess the potential impact of risks.
solutions ) A+ rated
Scope of Protection - correct answer ✔✔The protection provided by the European Union regulations,
which does not extend once you move outside its walls.
Facets of Risk Management - correct answer ✔✔Include Risk Assessment, Risk Measurement, Risk
Handling, Risk Tracking, Risk Management Lifecycle, and Risk Considerations.
Risk - correct answer ✔✔The probability that a threat will be realized and involves a continual balancing
act of a vulnerability against a threat.
Vulnerabilities - correct answer ✔✔Weaknesses in system design or implementation, such as software
bugs, misconfigured software, improperly protected network devices, and lacking physical security,
which can increase risk.
Threat - correct answer ✔✔Anything that could cause harm, loss, damage, or compromise to
information technology systems.
Relationship between Risk, Threats, and Vulnerabilities - correct answer ✔✔Risk exists in the
intersection area between threats and vulnerabilities, highlighting the importance of managing both to
minimize potential harm.
Risk Management - correct answer ✔✔Helps organizations minimize the likelihood of negative outcomes
and achieve desired outcomes while also putting controls in place to reduce risk to an acceptable level.
Risk Management Lifecycle - correct answer ✔✔Helps organizations identify and manage different risks,
implementing controls to bring the level of risk down to an acceptable level.
Examples of Vulnerabilities - correct answer ✔✔Include software bugs, misconfigured software,
improperly protected network devices, and lacking physical security.
,Risk Management and Legal Troubles - correct answer ✔✔By identifying and mitigating risks, risk
management can help organizations avoid situations that may lead to legal issues.
Purpose of Risk Management - correct answer ✔✔Ensures that we are able to establish trust and
mitigate liability.
Risk Identification - correct answer ✔✔Considers all types of risks or uncertainties that may impact
achieving a set of objectives.
NIST Framework - correct answer ✔✔Provides a framework aimed at establishing a strategic risk
management framework supported by key stakeholders.
Respond Phase - correct answer ✔✔Focuses on the mitigations put into place to lower the assessed risk.
Control - correct answer ✔✔Refers to the mitigations put into place to lower risk.
Categories of Control - correct answer ✔✔The 7 categories are People, Process, Technology, Protect,
Detect, Respond, and Restore/Recover.
Monitor Category - correct answer ✔✔Evaluates the effectiveness of risk response measures and
identifies changes that could affect risk management.
Formal Risk Analysis - correct answer ✔✔Conducted to determine risk levels and inform decision-
making.
Qualitative Risk Analysis - correct answer ✔✔Uses intuition, experience, and best practices to assign
non-numeric values to a given risk.
Methods in Qualitative Risk Analysis - correct answer ✔✔Include brainstorming sessions, focus groups,
and surveys.
,Delphi Method - correct answer ✔✔Involves estimating the likelihood of events occurring by gathering
expert opinions to assess proposed impact severity, loss potential, and likelihood of occurrence.
Quantitative Risk Analysis - correct answer ✔✔Uses numeric and monetary values for all parts of the risk
analysis to provide a measurable assessment of risks.
Equations in Risk Analysis - correct answer ✔✔Used to determine total and residual risk, providing a cost
directly associated with those risks.
Inherent Risk - correct answer ✔✔The level of risk identified before any mitigating actions are applied to
reduce its impact or likelihood.
Residual Risk - correct answer ✔✔The risk that remains after mitigation measures and security controls
have been applied.
Risk Exception - correct answer ✔✔Any risk created due to an exemption being granted or a failure to
comply with corporate policy.
Avoiding Risk Exceptions - correct answer ✔✔Organizations can avoid risk exceptions by implementing
strict compliance with corporate policies and not granting unnecessary exemptions.
Risk Avoidance - correct answer ✔✔A strategy that involves stopping a risky activity or choosing a less
risky alternative to eliminate hazards and exposures.
Risk Transfer - correct answer ✔✔Involves shifting the risk to another party, often through insurance or
outsourcing, to mitigate potential negative impacts.
Risk Mitigation - correct answer ✔✔A strategy that seeks to minimize the risk to an acceptable level that
an organization can accept.
Risk Acceptance - correct answer ✔✔A strategy that seeks to accept the current level of risk and the
costs associated with it.
, Risk Appetite - correct answer ✔✔Refers to the amount of risk that an organization is willing to accept in
pursuit of its objectives, also known as risk attitude or risk tolerance.
Risk Tracking - correct answer ✔✔Involves systematically tracking and evaluating the performance of risk
mitigation actions against established metrics throughout the lifecycle of an identified risk.
Risk Register - correct answer ✔✔A tool used to identify potential risks in a system or organization.
Components of a Risk Register - correct answer ✔✔Should include: Risk identified, Description, Level,
Likelihood, Owner, Mitigation measures implemented, and Residual level.
Owner in Risk Management - correct answer ✔✔The person responsible for managing the threats and
vulnerabilities that might exploit a specific risk.
Key Performance Indicators (KPIs) - correct answer ✔✔Metrics and numbers used to gauge and measure
different aspects of performance within an organization.
Scalability - correct answer ✔✔The ability of a system or process to handle a growing amount of work or
its potential to accommodate growth.
Reliability - correct answer ✔✔The measurement of the probability that the system will meet certain
performance standards and yield the correct output for a specific time.
Availability - correct answer ✔✔Refers to the percentage of time that the infrastructure, system, or
solution is operational under normal circumstances.
Key Risk Indicators (KRIs) - correct answer ✔✔Used to measure risk rather than system performance.
Risk Assessment - correct answer ✔✔A tool used during risk management to identify vulnerabilities and
assess the potential impact of risks.