Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 32 páginas
Examen

CNAB Exam with all Correct & 100% Verified Answers |Latest Version |Already Graded A+

Document preview thumbnail
Vista previa 4 fuera de 32 páginas

CNAB Exam with all Correct & 100% Verified Answers |Latest Version |Already Graded A+

Vista previa del contenido

SBOLC Security Fundamentals Exam with all Correct &
100% Verified Answers |Actual Complete Exam |Already
Graded A+

NIST ✔Correct Answer-National Institute of Standards and Technology

What is the NIST Risk Management Framework (RMF)? ✔Correct Answer--Overall framework
for the U.S. federal government to manage
organizational risk throughout the system development life cycle
-Focuses on security control selection, deployment, and auditing
using a seven-step model
-Includes certification and accreditation

Clean Desk Policy ✔Correct Answer-Secure sensitive items when not in use

Principle of least privilege management ✔Correct Answer-Just what you need to do your job

Mandatory vacations ✔Correct Answer--best way to uncover fraud
-part of onboarding procedures

Job Rotation (rotation of duties) ✔Correct Answer--Identify or uncover fraud
-Cross training / Experience for employees

Separation of Duties ✔Correct Answer-Partitions responsibilities to minimize abuse or fraud

Hiring and Termination Policy Elements ✔Correct Answer--Background checks
-Social media analysis
-Onboarding procedures (NDA/AUP/Sign for equipment)
-Offboarding procedures (NDA/Return of equipment)
-Exit interview
-Non-disclosure Agreement (NDA)

AUP ✔Correct Answer-Acceptable Use Policy

EOL ✔Correct Answer-End of Life

EOS ✔Correct Answer-End of Service

MOA ✔Correct Answer-Memorandum of Agreement

-A legally binding written document between multiple parties on a

,project detailing how they will work together to achieve
agreed-upon goals and objectives.

MOU ✔Correct Answer-Memorandum of Understanding

-A less formal agreement of mutual goals between two or more
organizations with a focus on partitioning of responsibilities

BPA ✔Correct Answer-Business Partners Agreement

-A written agreement defining the general relationship between
business partners with a focus on financial matters

Information Lifecycle Model ✔Correct Answer--Creation
-Processing
-Dissemination
-Usage
-Storage
-Disposal

Generic Information Classifications ✔Correct Answer--Low
-Medium
-High

Military Information Classifications ✔Correct Answer--Unclassified
-Confidential
-Secret
-Top Secret

Business Information Classifications ✔Correct Answer--Public
-Private
-Proprietary
-Confidential

Types of Protected Information ✔Correct Answer--Personally Identifiable Information (PII)
-Personal/Protected Health Information (PHI)
-Financial Information
-Government Data
-Customer Data

Risk Management ✔Correct Answer-The process of identifying, monitoring, and reducing risk
to an acceptable level.

Risk Analysis ✔Correct Answer--Threat (the potential to cause harm to an asset)

,-Vulnerability (a flaw or hole in the security posture)

-Exploit (a method or technique used to manipulate a faw)

-Safeguard (a mitigation security control)

Risk Management Strategies ✔Correct Answer--Acceptance: Have an established plan of
action

-Avoidance: Removing the activity that creates risk

-Transference: Offloading the risk to an external party

-Mitigation: Reducing risk by installing security control, safeguard, or countermeasures

Types of RIsk ✔Correct Answer--Externally-Derived Risk
-Internally-Derived Risk
-Legacy Systems
-Multiparty Involvement
-Intellectual Property Theft
-Software Compliance/Licensing Issues
-Inherent Risk
-Residual Risk

Qualitative Risk Assessment ✔Correct Answer-Based on human opinion or judgment derived
from interviews, surveys, benchmarking, scenario-based exercise, lessons learned analysis, or
cross-function workshops

Advantages of Qualitative Risk Assessment ✔Correct Answer--Impact is easily understood
-Can provide rich information beyond financial impacts, such as impact on perceived safety,
health, or reputation

Disadvantages of Qualitative Risk Assessment ✔Correct Answer--Prone to inaccuracy or
exaggeration
-Limited usefulness towards cost-benefit analysis

Quantitative Risk Assessment ✔Correct Answer--Requires numerical values or both impact
and likelihood using data from a variety of sources
-Can be used to support cost-benefit analysis calculations

Advantages to Quantitative Risk Assessment ✔Correct Answer--Supports cost-benefit analysis
of risk response options
-Allows computation of necessary capital to achieve a business goal

, Disadvantages to Quantitative RIsk Assessment ✔Correct Answer--Use of numbers may imply
greater precision than what truly exists
-Requires concrete units of measure that may cause obscure, or infrequent risk
from being recognized

Single Loss Expectancy (SLE) ✔Correct Answer-SLE = Asset Value (AV) x Exposure Factor (EF%)

Annualized Loss Expectancy (ALE) ✔Correct Answer-ALE = SLE x Annual Rate of Occurrence
(ARO)

Scenario: a building is worth $1,000,000, and a fire breaks out, consuming 70% of the building.
A fire occurs about once every 7 years in this geographical area. What is the SLE, and what is the
ALE? ✔Correct Answer--SLE = 1,000,000 x 70% =700,000

-ALE = 700,000 x 1/7 = 700,000/7 = 100,000

Mitigating Operational Risk ✔Correct Answer--Identify risk due to ongoing business
operations (risk control self-assessment/assessment)

-Assess the risk created due to business operations (likelihood and impact)

-Identify appropriate controls to mitigate the risk (control risk)

-Assessment of controls (identify control gaps)

Business Continuity Planning (BCP) ✔Correct Answer--The preventative and proactive
strategic plan to mitigate disruptive incidents to business operations
-Focuses on anticipating business operation disruptions

What does BCP identify ✔Correct Answer--Mission-essential functions
-Critical systems
-Single points of failure

Business Impact Analysis (BIA) ✔Correct Answer--A management tool that helps determine
the financial impact of business of organizational changes

Impact Considerations of BIA ✔Correct Answer--Safety
-Reputation
-Revenue
-Property

What are the different Common Site Implementations? ✔Correct Answer--Cold site - empty
facility with established power, HVAC, and network connectivity to the building

Información del documento

Subido en
4 de julio de 2026
Número de páginas
32
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$14.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
Studyclub
3.6
(14)
Vendido
65
Seguidores
1
Artículos
12651
Última venta
1 día hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes