EXAMINATION QUESTIONS WITH
ALL CORRECT ANSWERS
Prepare - Answer-First step of NIST RMF to manage security and privacy risks before a
breach
Ransomware - Answer-Malicious attack where data is encrypted and payment is
demanded
Risk - Answer-Anything impacting confidentiality, integrity, or availability of an asset
Risk mitigation - Answer-Process of having procedures and rules to quickly reduce risk
impact
Security posture - Answer-Organization's ability to manage defense of assets and react
to change
Select - Answer-Third step of NIST RMF to choose and document controls
Shared responsibility - Answer-Idea that all individuals in an organization lower risk and
maintain security
Categorize - Answer-Second step of NIST RMF to develop risk management processes
External threat - Answer-Anything outside the organization that can harm assets
Implement - Answer-Fourth step of NIST RMF to implement security and privacy plans
Internal threat - Answer-Current/former employee, vendor, or partner posing a security
risk
Monitor - Answer-Seventh step of NIST RMF to be aware of system operations
Social engineering - Answer-Manipulation technique exploiting human error to gain
private information
Vulnerability - Answer-Weakness that can be exploited by a threat