Security and Risk Management:
Questions and Answers already
passed
Which of the following is NOT a consideration for security professionals during mergers and
acquisitions?
A. new data types
B. new technology types
C. cost of the merger or acquisition
D. the other organization's security awareness training program - correct answer ✔✔ C
Explanation: A security professional should not be concerned with the cost of a merger or an
acquisition.
A security professional should only be concerned with issues that affect security and leave
financial issues to financial officers.
What is the first stage of the security program life cycle?
A. Plan and Organize
B. Implement
C. Operate and Maintain
D. Monitor and Evaluate - correct answer ✔✔ A
Explanation: The four stages of the security program life cycle, in order, are as follows:
, 1. Plan and Organization
2. Implement
3. Operate and Maintain
4. Monitor and Evaluate
Which term indicates the monetary impact of each threat occurrence?
A. ARO
B. ALE
C. EF
D. SLE - correct answer ✔✔ D
Explanation: SLE indicates the monetary impact of each threat occurrence. ARO is the estimate
of how often a given threat might occur annually. ALE is the expected risk factor of an annual
threat event. EF is the percent value or functionality of an asset that will be lost when a threat
event occurs.
Which management officer implements and manages all aspects of security, including risk
analysis, security policies and procedures, training, and emerging technologies?
A. CPO
B. CFO
C. CSO
D. CIO - correct answer ✔✔ Explanation: The chief security officer (CSO) is the officer that leads
any security effort and reports directly to the chief executive officer (CEO).
Questions and Answers already
passed
Which of the following is NOT a consideration for security professionals during mergers and
acquisitions?
A. new data types
B. new technology types
C. cost of the merger or acquisition
D. the other organization's security awareness training program - correct answer ✔✔ C
Explanation: A security professional should not be concerned with the cost of a merger or an
acquisition.
A security professional should only be concerned with issues that affect security and leave
financial issues to financial officers.
What is the first stage of the security program life cycle?
A. Plan and Organize
B. Implement
C. Operate and Maintain
D. Monitor and Evaluate - correct answer ✔✔ A
Explanation: The four stages of the security program life cycle, in order, are as follows:
, 1. Plan and Organization
2. Implement
3. Operate and Maintain
4. Monitor and Evaluate
Which term indicates the monetary impact of each threat occurrence?
A. ARO
B. ALE
C. EF
D. SLE - correct answer ✔✔ D
Explanation: SLE indicates the monetary impact of each threat occurrence. ARO is the estimate
of how often a given threat might occur annually. ALE is the expected risk factor of an annual
threat event. EF is the percent value or functionality of an asset that will be lost when a threat
event occurs.
Which management officer implements and manages all aspects of security, including risk
analysis, security policies and procedures, training, and emerging technologies?
A. CPO
B. CFO
C. CSO
D. CIO - correct answer ✔✔ Explanation: The chief security officer (CSO) is the officer that leads
any security effort and reports directly to the chief executive officer (CEO).