100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

(ISC)2 Certified in Cybersecurity - Exam Prep Questions With 100% Pass

Rating
-
Sold
-
Pages
67
Grade
A+
Uploaded on
09-09-2025
Written in
2025/2026

(ISC)2 Certified in Cybersecurity - Exam Prep Questions With 100% Pass /. Document specific requirements that a customer has about any aspect of a vendor's service performance. A) DLR B) Contract C) SLR D) NDA - Answer-C) SLR (Service-Level Requirements) /._________ identifies and triages risks. - Answer-Risk Assessment /._________ are external forces that jeopardize security. - Answer-Threats /._________ are methods used by attackers. - Answer-Threat Vectors /._________ are the combination of a threat and a vulnerability. - Answer-Risks /.We rank risks by _________ and _________. - Answer-Likelihood and impact /._________ use subjective ratings to evaluate risk likelihood and impact. - Answer-Qualitative Risk Assessment /._________ use objective numeric ratings to evaluate risk likelihood and impact. - Answer-Quantitative Risk Assessment /._________ analyzes and implements possible responses to control risk. - Answer-Risk Treatment /._________ changes business practices to make a risk irrelevant. - Answer-Risk Avoidance /._________ reduces the likelihood or impact of a risk. - Answer-Risk Mitigation /.An organization's _________ is the set of risks that it faces. - Answer-Risk Profile /._________ Initial Risk of an organization. - Answer-Inherent Risk /._________ Risk that remains in an organization after controls. - Answer-Residual Risk /._________ is the level of risk an organization is willing to accept. - Answer-Risk Tolerance /._________ reduce the likelihood or impact of a risk and help identify issues. - Answer-Security Controls /._________ stop a security issue from occurring. - Answer-Preventive Control /._________ identify security issues requiring investigation. - Answer-Detective Control /._________ remediate security issues that have occurred. - Answer-Recovery Control /.Hardening == Preventative - Answer-Virus == Detective /.Backups == Recovery - Answer-For exam (Local and Technical Controls are the same) /._________ use technology to achieve control objectives. - Answer-Technical Controls /._________ use processes to achieve control objectives. - Answer-Administrative Controls /._________ impact the physical world. - Answer-Physical Controls /._________ tracks specific device settings. - Answer-Configuration Management /._________ provide a configuration snapshot. - Answer-Baselines (track changes) /._________ assigns numbers to each version. - Answer-Versioning /._________ serve as important configuration artifacts. - Answer-Diagrams /._________ and _________ help ensure a stable operating environment. - Answer-Change and Configuration Management /.Purchasing an insurance policy is an example of which risk management strategy? - Answer-Risk Transference /.What two factors are used to evaluate a risk? - Answer-Likelihood and Impact /.What term best describes making a snapshot of a system or application at a point in time for later comparison? - Answer-Baselining /.What type of security control is designed to stop a security issue from occurring in the first place? - Answer-Preventive /.What term describes risks that originate inside the organization? - Answer-Internal /.What four items belong to the security policy framework? - Answer-Policies, Standards, Guidelines, Procedures /._________ describe an organization's security expectations. - Answer-Policies (mandatory and approved at the highest level of an organization) /._________ describe specific security controls and are often derived from policies. - Answer-Standards (mandatory) /._________ describe best practices. - Answer-Guidelines (recommendations/advice and compliance is not mandatory) /._________ step-by-step instructions. - Answer-Procedures (not mandatory) /._________ describe authorized uses of technology. - Answer-Acceptable Use Policies (AUP) /._________ describe how to protect sensitive information. - Answer-Data Handling Policies /._________ cover password security practices. - Answer-Password Policies /._________ cover use of personal devices with company information. - Answer-Bring Your Own Device (BYOD) Policies /._________ cover the use of personally identifiable information. - Answer-Privacy Policies /._________ cover the documentation, approval, and rollback of technology changes. - Answer-Change Management Policies /.Which element of the security policy framework includes suggestions that are not mandatory? - Answer-Guidelines /.What law applies to the use of personal information belonging to European Union residents? - Answer-GDPR /.What type of security policy normally describes how users may access business information with their own devices? - Answer-BYOD Policy /._________ the set of controls designed to keep a business running in the face of adversity, whether natural or man-made. - Answer-Business Continuity Planning (BCP) /.BCP is also known as _________. - Answer-Continuity of Operations Planning (COOP) /.Defining the BCP Scope: - Answer-What business activities will the plan cover? What systems will it cover? What controls will it consider? /._________ identifies and prioritizes risks. - Answer-Business Impact Assessment /.BCP in the cloud requires _________ between providers and customers. - Answer-Collaboration /._________ protects against the failure of a single component. - Answer-Redundancy /._________ identifies and removes SPOFs. - Answer-Single Point of Failure Analysis /._________ continues until the cost of addressing risks outweighs the benefit. - Answer-SPOF Analysis /._________ uses multiple systems to protect against service failure. - Answer-High Availability /._________ makes a single system resilient against technical failures. - Answer-Fault Tolerance /._________ spreads demand across systems. - Answer-Load Balancing /.3 Common Points of Failure in a system. - Answer-Power Supply, Storage Media, Networking /.Disk Mirroring is which RAID level? - Answer-1 /.Disk striping with parity is which RAID level? - Answer-5 (uses 3 or more disks to store data) /.What goal of security is enhanced by a strong business continuity program? - Answer-Availability /.What is the minimum number of disk required to perform RAID level 5? - Answer-3 /.What type of control are we using if we supplement a single firewall with a second standby firewall ready to assume responsibility if the primary firewall fails? - Answer-High Availability /._________ provide structure during cybersecurity incidents. - Answer-Incident Response Plan /._________ describe the policies and procedures governing cybersecurity incidents. - Answer-Incident Response Plans /._________ leads to strong incident response. - Answer-Prior Planning /.Incident Response Plans should include: - Answer-Statement of Purpose, Strategies and goals for incident response, Approach to incident response, Communication with other groups, Senior leadership approval /._________ should be consulted when developing a plan. - Answer-NIST SP 800-61 /.Incident response teams must have personnel available _________. - Answer-24/7 /._________ is crucial to effective incident identification. - Answer-Monitoring /._________ security solution that collects information from diverse sources, analyzes it for signs for security incidents and retains it for later use. - Answer-Security Incident and Event Management (SIEM) /.The highest priority of a first responder must be containing damage through _________. - Answer-Isolation /.During an incident response, what is the highest priority of first responders? - Answer-Containing the damage /.You are normally required to report security incidents to law enforcement if you believe a law may have been violated. True or False - Answer-False /._________ restores normal operations as quickly as possible. - Answer-Disaster Recovery /.What are the initial response goals regarding Disaster Recovery? - Answer-Contain the Damage, Recover normal operations /._________ is the amount of time to restore service. - Answer-Recovery Time Objective (RTO) /._________ is the amount of data to recover. - Answer-Recovery Point Objective (RPO) /._________ is the percentage of service to restore. - Answer-Recovery Service Level (RSL) /._________ provide a data "safety net" - Answer-Backups /.Types of Backup Media: - Answer-Tape backups, Disk-to-disk backups, Cloud backups /._________ include a complete copy of all data. - Answer-Full Backups

Show more Read less
Institution
2 Certified In Cybersecurity
Course
2 Certified in Cybersecurity











Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
2 Certified in Cybersecurity
Course
2 Certified in Cybersecurity

Document information

Uploaded on
September 9, 2025
Number of pages
67
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

(ISC)2 Certified in Cybersecurity -
Exam Prep Questions With 100% Pass
/. Document specific requirements that a customer has about any aspect of a vendor's
service performance.

A) DLR
B) Contract
C) SLR
D) NDA - Answer-C) SLR (Service-Level Requirements)

/._________ identifies and triages risks. - Answer-Risk Assessment

/._________ are external forces that jeopardize security. - Answer-Threats

/._________ are methods used by attackers. - Answer-Threat Vectors

/._________ are the combination of a threat and a vulnerability. - Answer-Risks

/.We rank risks by _________ and _________. - Answer-Likelihood and impact

/._________ use subjective ratings to evaluate risk likelihood and impact. - Answer-
Qualitative Risk Assessment

/._________ use objective numeric ratings to evaluate risk likelihood and impact. -
Answer-Quantitative Risk Assessment

/._________ analyzes and implements possible responses to control risk. - Answer-Risk
Treatment

/._________ changes business practices to make a risk irrelevant. - Answer-Risk
Avoidance

/._________ reduces the likelihood or impact of a risk. - Answer-Risk Mitigation

/.An organization's _________ is the set of risks that it faces. - Answer-Risk Profile

/._________ Initial Risk of an organization. - Answer-Inherent Risk

/._________ Risk that remains in an organization after controls. - Answer-Residual Risk

/._________ is the level of risk an organization is willing to accept. - Answer-Risk
Tolerance

,/._________ reduce the likelihood or impact of a risk and help identify issues. - Answer-
Security Controls

/._________ stop a security issue from occurring. - Answer-Preventive Control

/._________ identify security issues requiring investigation. - Answer-Detective Control

/._________ remediate security issues that have occurred. - Answer-Recovery Control

/.Hardening == Preventative - Answer-Virus == Detective

/.Backups == Recovery - Answer-For exam (Local and Technical Controls are the
same)

/._________ use technology to achieve control objectives. - Answer-Technical Controls

/._________ use processes to achieve control objectives. - Answer-Administrative
Controls

/._________ impact the physical world. - Answer-Physical Controls

/._________ tracks specific device settings. - Answer-Configuration Management

/._________ provide a configuration snapshot. - Answer-Baselines (track changes)

/._________ assigns numbers to each version. - Answer-Versioning

/._________ serve as important configuration artifacts. - Answer-Diagrams

/._________ and _________ help ensure a stable operating environment. - Answer-
Change and Configuration Management

/.Purchasing an insurance policy is an example of which risk management strategy? -
Answer-Risk Transference

/.What two factors are used to evaluate a risk? - Answer-Likelihood and Impact

/.What term best describes making a snapshot of a system or application at a point in
time for later comparison? - Answer-Baselining

/.What type of security control is designed to stop a security issue from occurring in the
first place? - Answer-Preventive

/.What term describes risks that originate inside the organization? - Answer-Internal

,/.What four items belong to the security policy framework? - Answer-Policies,
Standards, Guidelines, Procedures

/._________ describe an organization's security expectations. - Answer-Policies
(mandatory and approved at the highest level of an organization)

/._________ describe specific security controls and are often derived from policies. -
Answer-Standards (mandatory)

/._________ describe best practices. - Answer-Guidelines (recommendations/advice
and compliance is not mandatory)

/._________ step-by-step instructions. - Answer-Procedures (not mandatory)

/._________ describe authorized uses of technology. - Answer-Acceptable Use Policies
(AUP)

/._________ describe how to protect sensitive information. - Answer-Data Handling
Policies

/._________ cover password security practices. - Answer-Password Policies

/._________ cover use of personal devices with company information. - Answer-Bring
Your Own Device (BYOD) Policies

/._________ cover the use of personally identifiable information. - Answer-Privacy
Policies

/._________ cover the documentation, approval, and rollback of technology changes. -
Answer-Change Management Policies

/.Which element of the security policy framework includes suggestions that are not
mandatory? - Answer-Guidelines

/.What law applies to the use of personal information belonging to European Union
residents? - Answer-GDPR

/.What type of security policy normally describes how users may access business
information with their own devices? - Answer-BYOD Policy

/._________ the set of controls designed to keep a business running in the face of
adversity, whether natural or man-made. - Answer-Business Continuity Planning (BCP)

/.BCP is also known as _________. - Answer-Continuity of Operations Planning
(COOP)

, /.Defining the BCP Scope: - Answer-What business activities will the plan cover? What
systems will it cover? What controls will it consider?

/._________ identifies and prioritizes risks. - Answer-Business Impact Assessment

/.BCP in the cloud requires _________ between providers and customers. - Answer-
Collaboration

/._________ protects against the failure of a single component. - Answer-Redundancy

/._________ identifies and removes SPOFs. - Answer-Single Point of Failure Analysis

/._________ continues until the cost of addressing risks outweighs the benefit. -
Answer-SPOF Analysis

/._________ uses multiple systems to protect against service failure. - Answer-High
Availability

/._________ makes a single system resilient against technical failures. - Answer-Fault
Tolerance

/._________ spreads demand across systems. - Answer-Load Balancing

/.3 Common Points of Failure in a system. - Answer-Power Supply, Storage Media,
Networking

/.Disk Mirroring is which RAID level? - Answer-1

/.Disk striping with parity is which RAID level? - Answer-5 (uses 3 or more disks to store
data)

/.What goal of security is enhanced by a strong business continuity program? - Answer-
Availability

/.What is the minimum number of disk required to perform RAID level 5? - Answer-3

/.What type of control are we using if we supplement a single firewall with a second
standby firewall ready to assume responsibility if the primary firewall fails? - Answer-
High Availability

/._________ provide structure during cybersecurity incidents. - Answer-Incident
Response Plan

/._________ describe the policies and procedures governing cybersecurity incidents. -
Answer-Incident Response Plans

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
kartelodoc Harvard University
View profile
Follow You need to be logged in order to follow users or courses
Sold
120
Member since
1 year
Number of followers
4
Documents
8182
Last sold
1 week ago

Our store offers a wide selection of materials on various subjects and difficulty levels, created by experienced teachers. We specialize on NURSING,WGU,ACLS USMLE,TNCC,PMHNP,ATI and other major courses, Updated Exam, Study Guides and Test banks. If you don't find any document you are looking for in this store contact us and we will fetch it for you in minutes, we love impressing our clients with our quality work and we are very punctual on deadlines. Please go through the sets description appropriately before any purchase and leave a review after purchasing so as to make sure our customers are 100% satisfied. I WISH YOU SUCCESS IN YOUR EDUCATION JOURNEY

Read more Read less
3.2

22 reviews

5
7
4
1
3
7
2
3
1
4

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions