EXAM QUESTIONS AND ANSWERS
The process of determining potential risks that could affect an organization's ability to
achieve its objectives is called: - answer- Risk identification
The process of evaluating discovered risks to understand their potential impact and
likelihood is referred to as: - answer- Risk assessment
Which of the following answers refers to a risk assessment method based on need,
typically conducted in response to specific events or changes, such as after a major
organizational change or a security breach? - answer- Ad hoc
Which of the answers listed below refers to an example of recurring risk
assessment? - answer- Quarterly or annual risk assessments
Which of the following answers refers to a risk assessment conducted for a specific
purpose or project, without plans for regular reassessment (e.g., risk assessment for
a new product launch)? - answer- One-time
Which of the answers listed below refers to an example of continuous risk
assessment? - answer- Real-time monitoring of network security threats
Assessment of risk probability and its impact based on subjective judgment falls into
the category of: - answer- Qualitative risk assessment
A calculation of SLE(Single Loss Expectancy) is an example of: - answer-
Quantitative risk assessment
Which of the following terms is used to describe the predicted loss of value to an
asset based on a single security incident? - answer- SLE(Single Loss Expectancy)
Which of the acronyms listed below refers to a risk assessment formula defining
probable financial loss due to a risk over a one-year period? - answer- ALE(Annual
Loss Expectancy)
Which of the following answers refers to the correct formula for calculating probable
financial loss due to a risk over a one-year period? - answer- ALE (Annual Loss
Expectancy) = ARO(Annual Rate of Occurrence) x SLE (Single Loss Expectancy)
In quantitative risk assessment, this term is used for estimating the likelihood of
occurrence of a future threat. - answer- ARO(Annual Rate of Occurrence)
An estimate based on the historical data of how often a threat would be successful in
exploiting a vulnerability is known as: - answer- ARO(Annual Rate of Occurrence)