Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 134 pages
Exam (elaborations)

(ISC)2 Certified in Cybersecurity - Exam Prep Questions And Answers

Document preview thumbnail
Preview 4 out of 134 pages

©SIRJOEL EXAM SOLUTIONS 2024/2025 ALL RIGHTS RESERVED. 2 | P a g e _________ use subjective ratings to evaluate risk likelihood and impact. - AnswersQualitative Risk Assessment _________ use objective numeric ratings to evaluate risk likelihood and impact. - AnswersQuantitative Risk Assessment _________ analyzes and implements possible responses to control risk. - AnswersRisk Treatment _________ changes business practices to make a risk irrelevant. - AnswersRisk Avoidance _________ reduces the likelihood or impact of a risk. - AnswersRisk Mitigation An organization's _________ is the set of risks that it faces. - AnswersRisk Profile _________ Initial Risk of an organization. - AnswersInherent Risk _________ Risk that remains in an organization after controls. - AnswersResidual Risk _________ is the level of risk an organization is willing to accept. - AnswersRisk Tolerance _________ reduce the likelihood or impact of a risk and help identify issues. - AnswersSecurity Controls _________ stop a security issue from occurring. - AnswersPreventive Control _________ identify security issues requiring investigation. - AnswersDetective Control _________ remediate security issues that have occurred. - AnswersRecovery Control ©SIRJOEL EXAM SOLUTIONS 2024/2025 ALL RIGHTS RESERVED. 3 | P a g e Hardening == Preventative - AnswersVirus == Detective Backups == Recovery - AnswersFor exam (Local and Technical Controls are the same) _________ use technology to achieve control objectives. - AnswersTechnical Controls _________ use processes to achieve control objectives. - AnswersAdministrative Controls _________ impact the physical world. - AnswersPhysical Controls _________ tracks specific device settings. - AnswersConfiguration Management _________ provide a configuration snapshot. - AnswersBaselines (track changes) _________ assigns numbers to each version. - AnswersVersioning _________ serve as important configuration artifacts. - AnswersDiagrams _________ and _________ help ensure a stable operating environment. - AnswersChange and Configuration Management Purchasing an insurance policy is an example of which risk management strategy? - AnswersRisk Transference What two factors are used to evaluate a risk? - AnswersLikelihood and Impact What term best describes making a snapshot of a system or application at a point in time for later comparison? - AnswersBaselining ©SIRJOEL EXAM SOLUTIONS 2024/2025 ALL RIGHTS RESERVED. 4 | P a g e What type of security control is designed to stop a security issue from occurring in the first place? - AnswersPreventive What term describes risks that originate inside the organization? - AnswersInternal What four items belong to the security policy framework? - AnswersPolicies, Standards, Guidelines, Procedures _________ describe an organization's security expectations. - AnswersPolicies (mandatory and approved at the highest level of an organization) _________ describe specific security controls and are often derived from policies. - AnswersStandards (mandatory) _________ describe best practices. - AnswersGuidelines (recommendations/advice and compliance is not mandatory) _________ step-by-step instructions. - AnswersProcedures (not mandatory) _________ describe authorized uses of technology. - AnswersAcceptable Use Policies (AUP) _________ describe how to protect sensitive information. - AnswersData Handling Policies _________ cover password security practices. - AnswersPassword Policies _________ cover use of personal devices with company information. - AnswersBring Your Own Device (BYOD) Policies

Content preview

©SIRJOEL EXAM SOLUTIONS 2024/2025

ALL RIGHTS RESERVED.




(ISC)2 Certified in Cybersecurity - Exam
Prep Questions And Answers

Document specific requirements that a customer has about any aspect of a vendor's service

performance.




A) DLR


B) Contract


C) SLR


D) NDA - Answers✔C) SLR (Service-Level Requirements)


_________ identifies and triages risks. - Answers✔Risk Assessment


_________ are external forces that jeopardize security. - Answers✔Threats


_________ are methods used by attackers. - Answers✔Threat Vectors


_________ are the combination of a threat and a vulnerability. - Answers✔Risks


We rank risks by _________ and _________. - Answers✔Likelihood and impact




1|Page

, ©SIRJOEL EXAM SOLUTIONS 2024/2025

ALL RIGHTS RESERVED.
_________ use subjective ratings to evaluate risk likelihood and impact. - Answers✔Qualitative

Risk Assessment


_________ use objective numeric ratings to evaluate risk likelihood and impact. -

Answers✔Quantitative Risk Assessment


_________ analyzes and implements possible responses to control risk. - Answers✔Risk

Treatment


_________ changes business practices to make a risk irrelevant. - Answers✔Risk Avoidance


_________ reduces the likelihood or impact of a risk. - Answers✔Risk Mitigation


An organization's _________ is the set of risks that it faces. - Answers✔Risk Profile


_________ Initial Risk of an organization. - Answers✔Inherent Risk


_________ Risk that remains in an organization after controls. - Answers✔Residual Risk


_________ is the level of risk an organization is willing to accept. - Answers✔Risk Tolerance


_________ reduce the likelihood or impact of a risk and help identify issues. -

Answers✔Security Controls


_________ stop a security issue from occurring. - Answers✔Preventive Control


_________ identify security issues requiring investigation. - Answers✔Detective Control


_________ remediate security issues that have occurred. - Answers✔Recovery Control


2|Page

, ©SIRJOEL EXAM SOLUTIONS 2024/2025

ALL RIGHTS RESERVED.
Hardening == Preventative - Answers✔Virus == Detective


Backups == Recovery - Answers✔For exam (Local and Technical Controls are the same)


_________ use technology to achieve control objectives. - Answers✔Technical Controls


_________ use processes to achieve control objectives. - Answers✔Administrative Controls


_________ impact the physical world. - Answers✔Physical Controls


_________ tracks specific device settings. - Answers✔Configuration Management


_________ provide a configuration snapshot. - Answers✔Baselines (track changes)


_________ assigns numbers to each version. - Answers✔Versioning


_________ serve as important configuration artifacts. - Answers✔Diagrams


_________ and _________ help ensure a stable operating environment. - Answers✔Change

and Configuration Management


Purchasing an insurance policy is an example of which risk management strategy? -

Answers✔Risk Transference


What two factors are used to evaluate a risk? - Answers✔Likelihood and Impact


What term best describes making a snapshot of a system or application at a point in time for

later comparison? - Answers✔Baselining




3|Page

, ©SIRJOEL EXAM SOLUTIONS 2024/2025

ALL RIGHTS RESERVED.
What type of security control is designed to stop a security issue from occurring in the first

place? - Answers✔Preventive


What term describes risks that originate inside the organization? - Answers✔Internal


What four items belong to the security policy framework? - Answers✔Policies, Standards,

Guidelines, Procedures


_________ describe an organization's security expectations. - Answers✔Policies (mandatory

and approved at the highest level of an organization)


_________ describe specific security controls and are often derived from policies. -

Answers✔Standards (mandatory)


_________ describe best practices. - Answers✔Guidelines (recommendations/advice and

compliance is not mandatory)


_________ step-by-step instructions. - Answers✔Procedures (not mandatory)


_________ describe authorized uses of technology. - Answers✔Acceptable Use Policies (AUP)


_________ describe how to protect sensitive information. - Answers✔Data Handling Policies


_________ cover password security practices. - Answers✔Password Policies


_________ cover use of personal devices with company information. - Answers✔Bring Your

Own Device (BYOD) Policies



4|Page

Document information

Uploaded on
December 10, 2024
Number of pages
134
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$12.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
sirjoel
3.6
(18)
Sold
134
Followers
13
Items
12780
Last sold
4 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions