Question 1 points
Residual risk is defined as
Question options:
The total risk that exists
Risk from a 3rd party vendor
Risk that is harmless
Risk that remains after controls are implemented
Hide question 1 feedback
Feedback
Correct!
Question 2 points
A security policy must be so written that it can be understood by
Question options:
The Security Team
The CEO
The CISO
Its Target Audience
, Hide question 2 feedback
Feedback
Correct!
Question 3 points
The risk treatment option of making changes to an activity or forgoing the activity to remove
the risk and eliminate its effect is known as
Question options:
Risk Sharing or Transfer
Risk Avoidance or Elimination
Risk Modification or Mitigation
Risk Retention or Acceptance
Hide question 3 feedback
Feedback
Correct!
Question 4 points
How often should higher risk-rated applications be reviewed?
Question options:
Annually
Every Other Year
Quarterly