Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

(ISC)2 Certified in Cybersecurity - Exam Prep|Comlete Questions with 100% Correct Answers

Beoordeling
-
Verkocht
-
Pagina's
70
Cijfer
A+
Geüpload op
05-04-2024
Geschreven in
2023/2024

(ISC)2 Certified in Cybersecurity - Exam Prep|Comlete Questions with 100% Correct Answers Document specific requirements that a customer has about any aspect of a vendor's service performance. A) DLR B) Contract C) SLR D) NDA C) SLR (Service-Level Requirements) _________ identifies and triages risks. Risk Assessment _________ are external forces that jeopardize security. Threats _________ are methods used by attackers. Threat Vectors _________ are the combination of a threat and a vulnerability. Risks We rank risks by _________ and _________. Likelihood and impact _________ use subjective ratings to evaluate risk likelihood and impact. Qualitative Risk Assessment _________ use objective numeric ratings to evaluate risk likelihood and impact. Quantitative Risk Assessment _________ analyzes and implements possible responses to control risk. Risk Treatment _________ changes business practices to make a risk irrelevant. Risk Avoidance _________ reduces the likelihood or impact of a risk. Risk Mitigation An organization's _________ is the set of risks that it faces. Risk Profile

Meer zien Lees minder
Instelling
Vak

Voorbeeld van de inhoud

(ISC)2 Certified in Cybersecurity - Exam Prep|Comlete
Questions with 100% Correct Answers
Document specific requirements that a customer has about any aspect of a vendor's service
performance.

A) DLR
B) Contract
C) SLR
D) NDA
C) SLR (Service-Level Requirements)


_________ identifies and triages risks.
Risk Assessment


_________ are external forces that jeopardize security.
Threats


_________ are methods used by attackers.
Threat Vectors


_________ are the combination of a threat and a vulnerability.
Risks


We rank risks by _________ and _________.
Likelihood and impact


_________ use subjective ratings to evaluate risk likelihood and impact.
Qualitative Risk Assessment


_________ use objective numeric ratings to evaluate risk likelihood and impact.
Quantitative Risk Assessment


_________ analyzes and implements possible responses to control risk.
Risk Treatment


_________ changes business practices to make a risk irrelevant.
Risk Avoidance


_________ reduces the likelihood or impact of a risk.
Risk Mitigation


An organization's _________ is the set of risks that it faces.
Risk Profile

,_________ Initial Risk of an organization.
Inherent Risk


_________ Risk that remains in an organization after controls.
Residual Risk


_________ is the level of risk an organization is willing to accept.
Risk Tolerance


_________ reduce the likelihood or impact of a risk and help identify issues.
Security Controls


_________ stop a security issue from occurring.
Preventive Control


_________ identify security issues requiring investigation.
Detective Control


_________ remediate security issues that have occurred.
Recovery Control


Hardening == Preventative
Virus == Detective


Backups == Recovery
For exam (Local and Technical Controls are the same)


_________ use technology to achieve control objectives.
Technical Controls


_________ use processes to achieve control objectives.
Administrative Controls


_________ impact the physical world.
Physical Controls


_________ tracks specific device settings.
Configuration Management


_________ provide a configuration snapshot.
Baselines (track changes)


_________ assigns numbers to each version.

,Versioning


_________ serve as important configuration artifacts.
Diagrams


_________ and _________ help ensure a stable operating environment.
Change and Configuration Management


Purchasing an insurance policy is an example of which risk management strategy?
Risk Transference


What two factors are used to evaluate a risk?
Likelihood and Impact


What term best describes making a snapshot of a system or application at a point in time for later
comparison?
Baselining


What type of security control is designed to stop a security issue from occurring in the first place?
Preventive


What term describes risks that originate inside the organization?
Internal


What four items belong to the security policy framework?
Policies, Standards, Guidelines, Procedures


_________ describe an organization's security expectations.
Policies (mandatory and approved at the highest level of an organization)


_________ describe specific security controls and are often derived from policies.
Standards (mandatory)


_________ describe best practices.
Guidelines (recommendations/advice and compliance is not mandatory)


_________ step-by-step instructions.
Procedures (not mandatory)


_________ describe authorized uses of technology.
Acceptable Use Policies (AUP)


_________ describe how to protect sensitive information.

, Data Handling Policies


_________ cover password security practices.
Password Policies


_________ cover use of personal devices with company information.
Bring Your Own Device (BYOD) Policies


_________ cover the use of personally identifiable information.
Privacy Policies


_________ cover the documentation, approval, and rollback of technology changes.
Change Management Policies


Which element of the security policy framework includes suggestions that are not mandatory?
Guidelines


What law applies to the use of personal information belonging to European Union residents?
GDPR


What type of security policy normally describes how users may access business information with their
own devices?
BYOD Policy


_________ the set of controls designed to keep a business running in the face of adversity, whether
natural or man-made.
Business Continuity Planning (BCP)


BCP is also known as _________.
Continuity of Operations Planning (COOP)


Defining the BCP Scope:
What business activities will the plan cover? What systems will it cover? What controls will it
consider?


_________ identifies and prioritizes risks.
Business Impact Assessment


BCP in the cloud requires _________ between providers and customers.
Collaboration


_________ protects against the failure of a single component.
Redundancy

Geschreven voor

Vak

Documentinformatie

Geüpload op
5 april 2024
Aantal pagina's
70
Geschreven in
2023/2024
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

$25.49
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF


Ook beschikbaar in voordeelbundel

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
LectDeniz Teachme2-tutor
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
21
Lid sinds
2 jaar
Aantal volgers
13
Documenten
4965
Laatst verkocht
7 maanden geleden
Lect Deniz Academic Resources Hub

Lect Deniz is a highly experienced academic tutor and dedicated content creator with a strong track record of developing comprehensive, high-quality study materials for a wide range of university courses across the globe. With years of experience in higher education support, he excels at transforming complex academic concepts into clear, structured, and easy-to-follow resources that enhance student understanding and confidence. He provides an extensive collection of well-researched and carefully organized documents across key disciplines, including nursing, medicine, and various science fields. His materials cover essential topics such as anatomy, physiology, pharmacology, clinical practice, and core scientific principles, making them highly valuable for both coursework and intensive exam preparation. Each document is thoughtfully designed to align with university standards and curricula, ensuring accuracy, relevance, and practical application. Lect Aziim’s work stands out for its clarity, depth, and attention to detail, offering students concise summaries, detailed explanations, and exam-focused content that supports effective revision. His commitment to academic excellence and student success is reflected in the consistency and reliability of his materials, making him a trusted resource for learners seeking to improve performance and achieve their academic goals.

Lees meer Lees minder
5.0

1 beoordelingen

5
1
4
0
3
0
2
0
1
0

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen