100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

(ISC)2 Certified in Cybersecurity - Exam Prep Test with 100% Verified Answers Graded A+

Rating
-
Sold
-
Pages
114
Grade
A+
Uploaded on
20-04-2025
Written in
2024/2025

Document specific requirements that a customer has about any aspect of a vendor's service performance. A) DLR B) Contract C) SLR D) NDA - -C) SLR (Service-Level Requirements) _________ identifies and triages risks. - -Risk Assessment _________ are external forces that jeopardize security. - -Threats _________ are methods used by attackers. - -Threat Vectors _________ are the combination of a threat and a vulnerability. - -Risks We rank risks by _________

Show more Read less
Institution
2 Certified In Cybersecurity
Course
2 Certified in Cybersecurity











Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
2 Certified in Cybersecurity
Course
2 Certified in Cybersecurity

Document information

Uploaded on
April 20, 2025
Number of pages
114
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

(ISC)2 Certified in Cybersecurity - Exam Prep Test
with 100% Verified Answers Graded A+
Document specific requirements that a customer has about any aspect of a vendor's
Page | 1
service performance.



A) DLR

B) Contract

C) SLR

D) NDA - -C) SLR (Service-Level Requirements)



_________ identifies and triages risks. - -Risk Assessment



_________ are external forces that jeopardize security. - -Threats



_________ are methods used by attackers. - -Threat Vectors



_________ are the combination of a threat and a vulnerability. - -Risks



We rank risks by _________ and _________. - -Likelihood and impact



_________ use subjective ratings to evaluate risk likelihood and impact. - -Qualitative
Risk Assessment



_________ use objective numeric ratings to evaluate risk likelihood and impact. - -
Quantitative Risk Assessment

, _________ analyzes and implements possible responses to control risk. - -Risk
Treatment
Page | 2

_________ changes business practices to make a risk irrelevant. - -Risk Avoidance



_________ reduces the likelihood or impact of a risk. - -Risk Mitigation



An organization's _________ is the set of risks that it faces. - -Risk Profile



_________ Initial Risk of an organization. - -Inherent Risk



_________ Risk that remains in an organization after controls. - -Residual Risk



_________ is the level of risk an organization is willing to accept. - -Risk Tolerance



_________ reduce the likelihood or impact of a risk and help identify issues. - -
Security Controls



_________ stop a security issue from occurring. - -Preventive Control



_________ identify security issues requiring investigation. - -Detective Control



_________ remediate security issues that have occurred. - -Recovery Control

, Hardening == Preventative - -Virus == Detective



Backups == Recovery - -For exam (Local and Technical Controls are the same)
Page | 3


_________ use technology to achieve control objectives. - -Technical Controls



_________ use processes to achieve control objectives. - -Administrative Controls



_________ impact the physical world. - -Physical Controls



_________ tracks specific device settings. - -Configuration Management



_________ provide a configuration snapshot. - -Baselines (track changes)



_________ assigns numbers to each version. - -Versioning



_________ serve as important configuration artifacts. - -Diagrams



_________ and _________ help ensure a stable operating environment. - -Change and
Configuration Management



Purchasing an insurance policy is an example of which risk management strategy? - -
Risk Transference



What two factors are used to evaluate a risk? - -Likelihood and Impact

, What term best describes making a snapshot of a system or application at a point in time
for later comparison? - -Baselining

Page | 4

What type of security control is designed to stop a security issue from occurring in the first
place? - -Preventive



What term describes risks that originate inside the organization? - -Internal



What four items belong to the security policy framework? - -Policies, Standards,
Guidelines, Procedures



_________ describe an organization's security expectations. - -Policies (mandatory
and approved at the highest level of an organization)



_________ describe specific security controls and are often derived from policies. - -
Standards (mandatory)



_________ describe best practices. - -Guidelines (recommendations/advice and
compliance is not mandatory)



_________ step-by-step instructions. - -Procedures (not mandatory)



_________ describe authorized uses of technology. - -Acceptable Use Policies (AUP)



_________ describe how to protect sensitive information. - -Data Handling Policies

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
MERCYTRISHIA Howard Community College
View profile
Follow You need to be logged in order to follow users or courses
Sold
183
Member since
1 year
Number of followers
35
Documents
10800
Last sold
14 hours ago
MercyTrishia

On this page, you find all documents, package deals offered by seller MercyTrishia

3.8

37 reviews

5
16
4
7
3
10
2
0
1
4

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions