CSIA 350 Assignment 2 e-Commerce
Risk Analysis | UMGC Cybersecurity
Risk Assessment Study Guide |
2026/2027
1. What is the primary goal of an e-commerce risk analysis?
A. To eliminate all risks entirely.
B. To identify, assess, and prioritize risks to an organization's e-commerce assets.
C. To create a marketing plan for the e-commerce platform.
D. To ensure the website has an attractive design.
Correct Answer: B
Rationale: The core purpose of risk analysis is not to eliminate all risk (which is impossible),
but to understand the risks the organization faces so that resources can be allocated effectively
to mitigate the most significant ones. This involves identifying, assessing, and prioritizing risks to
the e-commerce assets that support the business.
2. In the context of e-commerce, what does the term "asset" refer to?
A. Only the physical servers hosting the website.
B. Any item of value to the organization, including data, systems, and reputation.
C. The financial capital invested in the e-commerce platform.
D. The company's stock price.
Correct Answer: B
Rationale: In risk management, an asset is anything of value to the organization. For an e-
commerce business, this includes not just physical hardware but also intangible assets like
customer data, intellectual property, brand reputation, and the trust of its users.
,3. Which of the following is NOT one of the three components of the classic risk formula?
A. Threat
B. Vulnerability
C. Impact
D. Marketing Budget
Correct Answer: D
Rationale: The classic risk formula is often expressed as Risk = Threat x Vulnerability x
Impact. The marketing budget is a business expense and does not directly factor into the
calculation of a specific security risk.
4. A "threat" in e-commerce risk analysis is best defined as:
A. A weakness in the system that can be exploited.
B. The potential for a negative event to occur.
C. Any circumstance or event with the potential to adversely impact organizational operations
or assets.
D. The monetary loss from a security breach.
Correct Answer: C
Rationale: A threat is any potential cause of an unwanted incident, which may result in
harm to a system or organization. This includes natural disasters, malicious actors, and
accidental errors.
5. A "vulnerability" is:
A. A weakness in an asset or control that can be exploited by a threat.
B. The likelihood of a threat occurring.
C. The total cost of a security breach.
D. A type of hacker.
Correct Answer: A
Rationale: A vulnerability is a flaw or weakness in a system's design, implementation, or
operation that could be exploited to violate the system's security policy. It's the "hole" that a
threat can use.
6. What is the primary purpose of a risk assessment?
A. To guarantee that no security breaches will ever happen.
,B. To provide a snapshot of the current risks and inform decision-making for risk treatment.
C. To assign blame for past security incidents.
D. To purchase the most expensive security tools available.
Correct Answer: B
Rationale: A risk assessment is a point-in-time evaluation. Its goal is to understand the
current risk landscape so that management can make informed decisions about which risks to
mitigate, transfer, avoid, or accept.
7. In e-commerce, "PII" stands for:
A. Public Information Interface
B. Personal Internet Identity
C. Personally Identifiable Information
D. Payment Integration Infrastructure
Correct Answer: C
Rationale: Personally Identifiable Information (PII) is any data that could potentially identify
a specific individual. This is a critical asset to protect in any e-commerce transaction.
8. Which of the following is a common threat actor in the e-commerce space?
A. Script Kiddies
B. Organized Crime Groups
C. Hacktivists
D. All of the above
Correct Answer: D
Rationale: E-commerce platforms are attractive targets for a wide range of threat actors.
Script kiddies may deface sites for fun, organized crime seeks financial gain through fraud and
data theft, and hacktivists may target a company for ideological reasons.
9. What does PCI DSS stand for?
A. Payment Card Industry Data Security Standard
B. Personal Cybersecurity Incident Data System
C. Protocol for Commercial Internet Data Security
D. Private Customer Information Data Standard
, Correct Answer: A
Rationale: The Payment Card Industry Data Security Standard (PCI DSS) is a set of security
standards designed to ensure that all companies that accept, process, store or transmit credit
card information maintain a secure environment.
10. The primary reason an e-commerce business must comply with PCI DSS is to:
A. Improve website loading speed.
B. Protect cardholder data and avoid fines and penalties from card brands.
C. Increase sales through better marketing.
D. Reduce the cost of web hosting.
Correct Answer: B
Rationale: PCI DSS compliance is mandated by the credit card brands (Visa, Mastercard,
etc.). Non-compliance can result in hefty fines, loss of the ability to process credit card
payments, and severe reputational damage.
11. What is a "SQL Injection" attack?
A. An attack that overwhelms a server with traffic.
B. An attack that inserts malicious code into a database query via user input fields.
C. An attack that tricks a user into revealing their password.
D. An attack that physically steals a server.
Correct Answer: B
Rationale: SQL Injection is a code injection technique that exploits a vulnerability in an
application's database layer. It allows an attacker to interfere with the queries an application
makes to its database, potentially accessing or modifying sensitive data.
12. Which of the following is the best defense against SQL Injection attacks?
A. Using a Web Application Firewall (WAF).
B. Storing all data in plain text.
C. Using parameterized queries (prepared statements).
D. Changing the database administrator's password every day.
Correct Answer: C
Rationale: Parameterized queries ensure that user input is treated as data, not as
Risk Analysis | UMGC Cybersecurity
Risk Assessment Study Guide |
2026/2027
1. What is the primary goal of an e-commerce risk analysis?
A. To eliminate all risks entirely.
B. To identify, assess, and prioritize risks to an organization's e-commerce assets.
C. To create a marketing plan for the e-commerce platform.
D. To ensure the website has an attractive design.
Correct Answer: B
Rationale: The core purpose of risk analysis is not to eliminate all risk (which is impossible),
but to understand the risks the organization faces so that resources can be allocated effectively
to mitigate the most significant ones. This involves identifying, assessing, and prioritizing risks to
the e-commerce assets that support the business.
2. In the context of e-commerce, what does the term "asset" refer to?
A. Only the physical servers hosting the website.
B. Any item of value to the organization, including data, systems, and reputation.
C. The financial capital invested in the e-commerce platform.
D. The company's stock price.
Correct Answer: B
Rationale: In risk management, an asset is anything of value to the organization. For an e-
commerce business, this includes not just physical hardware but also intangible assets like
customer data, intellectual property, brand reputation, and the trust of its users.
,3. Which of the following is NOT one of the three components of the classic risk formula?
A. Threat
B. Vulnerability
C. Impact
D. Marketing Budget
Correct Answer: D
Rationale: The classic risk formula is often expressed as Risk = Threat x Vulnerability x
Impact. The marketing budget is a business expense and does not directly factor into the
calculation of a specific security risk.
4. A "threat" in e-commerce risk analysis is best defined as:
A. A weakness in the system that can be exploited.
B. The potential for a negative event to occur.
C. Any circumstance or event with the potential to adversely impact organizational operations
or assets.
D. The monetary loss from a security breach.
Correct Answer: C
Rationale: A threat is any potential cause of an unwanted incident, which may result in
harm to a system or organization. This includes natural disasters, malicious actors, and
accidental errors.
5. A "vulnerability" is:
A. A weakness in an asset or control that can be exploited by a threat.
B. The likelihood of a threat occurring.
C. The total cost of a security breach.
D. A type of hacker.
Correct Answer: A
Rationale: A vulnerability is a flaw or weakness in a system's design, implementation, or
operation that could be exploited to violate the system's security policy. It's the "hole" that a
threat can use.
6. What is the primary purpose of a risk assessment?
A. To guarantee that no security breaches will ever happen.
,B. To provide a snapshot of the current risks and inform decision-making for risk treatment.
C. To assign blame for past security incidents.
D. To purchase the most expensive security tools available.
Correct Answer: B
Rationale: A risk assessment is a point-in-time evaluation. Its goal is to understand the
current risk landscape so that management can make informed decisions about which risks to
mitigate, transfer, avoid, or accept.
7. In e-commerce, "PII" stands for:
A. Public Information Interface
B. Personal Internet Identity
C. Personally Identifiable Information
D. Payment Integration Infrastructure
Correct Answer: C
Rationale: Personally Identifiable Information (PII) is any data that could potentially identify
a specific individual. This is a critical asset to protect in any e-commerce transaction.
8. Which of the following is a common threat actor in the e-commerce space?
A. Script Kiddies
B. Organized Crime Groups
C. Hacktivists
D. All of the above
Correct Answer: D
Rationale: E-commerce platforms are attractive targets for a wide range of threat actors.
Script kiddies may deface sites for fun, organized crime seeks financial gain through fraud and
data theft, and hacktivists may target a company for ideological reasons.
9. What does PCI DSS stand for?
A. Payment Card Industry Data Security Standard
B. Personal Cybersecurity Incident Data System
C. Protocol for Commercial Internet Data Security
D. Private Customer Information Data Standard
, Correct Answer: A
Rationale: The Payment Card Industry Data Security Standard (PCI DSS) is a set of security
standards designed to ensure that all companies that accept, process, store or transmit credit
card information maintain a secure environment.
10. The primary reason an e-commerce business must comply with PCI DSS is to:
A. Improve website loading speed.
B. Protect cardholder data and avoid fines and penalties from card brands.
C. Increase sales through better marketing.
D. Reduce the cost of web hosting.
Correct Answer: B
Rationale: PCI DSS compliance is mandated by the credit card brands (Visa, Mastercard,
etc.). Non-compliance can result in hefty fines, loss of the ability to process credit card
payments, and severe reputational damage.
11. What is a "SQL Injection" attack?
A. An attack that overwhelms a server with traffic.
B. An attack that inserts malicious code into a database query via user input fields.
C. An attack that tricks a user into revealing their password.
D. An attack that physically steals a server.
Correct Answer: B
Rationale: SQL Injection is a code injection technique that exploits a vulnerability in an
application's database layer. It allows an attacker to interfere with the queries an application
makes to its database, potentially accessing or modifying sensitive data.
12. Which of the following is the best defense against SQL Injection attacks?
A. Using a Web Application Firewall (WAF).
B. Storing all data in plain text.
C. Using parameterized queries (prepared statements).
D. Changing the database administrator's password every day.
Correct Answer: C
Rationale: Parameterized queries ensure that user input is treated as data, not as