QUESTIONS WITH CORRECT ANSWERS
GRADED A+
◉ Which role always has ultimate responsibility for security in an
organization? Answer: Senior Manager
◉ What is the goal of most Cyber Threats today? Answer: Make money
for the attacker
◉ What is the name of the role with primary responsibility for data?
Answer: Data Owner
◉ What role is responsible for implementing controls on data? Answer:
Data Custodian
◉ The term due care means that senior management has a legal
responsibility to. Answer: Act as a reasonable person would act in
protecting assets
◉ Who in the organization determines if risk is acceptable? Answer:
Chief Executive Officer (CEO)
, ◉ The term Exposure Factor means. Answer: The percentage of asset
value loss
◉ The term Single Loss Expectancy means. Answer: What is costs each
time a threat materializes
◉ The formula to arrive at Annual Loss Expectancy is. Answer: Annual
Rate of Occurance * Single Loss Expectancy
◉ The formula to arrive at Single Loss Expectancy is. Answer: Asset
Value * Exposure Factor
◉ Which approach to Risk Assessment is based on money? Answer:
Quantitative
◉ Which approach to Risk Assessment is based on severity and
likelihood? Answer: Qualitative
◉ Of the three control areas, which deals with authentication? Answer:
Technical Controls
◉ Of the three control types, which deals with authentication? Answer:
Preventive