answers
___________ assessments are objective, while ________________
assessments are subjective Ans✓✓✓ Quantitative, Qualitative
___________ negatively affect(s) the CIA triad Ans✓✓✓ Threats
______________ is the likelihood that a threat will exploit a
vulnerability Ans✓✓✓ Probability
A _______________ is the likelihood that a loss will occur. Ans✓✓✓
Risk
A BIA typically identifies the customers and how the organization plans
to serve them Ans✓✓✓ False
A business impact analysis is concerned with identifying and
implementing recovery methods Ans✓✓✓ False
A business impact analysis is intended to include all IT functions
Ans✓✓✓ Flase
A key step in managing risk is to first understand and manage the
source. Ans✓✓✓ True
, A relative measurement of a resource's tolerance for risk exposure is:
Ans✓✓✓ Risk Sensitivity
A Risk Management team should focus both on critical areas and on
what management might consider important. Ans✓✓✓ True
A risk rating calculation = Ans✓✓✓ Likelihood of vulnerability X
value of asset - % mitigated risks + uncertainty
A security scan and a risk assessment are the same Ans✓✓✓ False
A(n) _______ is the process of creating a list of threats Ans✓✓✓
Threat Identification
According to Landoll, which of the following is NOT a type of security
test? Ans✓✓✓ Threat testing
According to Talabis, what is the function of a BIA? Ans✓✓✓ To
assess and identify critical and non-critical organizational functions and
activities.
According to Talabis, what is the most rigorous and most encompassing
activity in the information security risk assessment process? Ans✓✓✓
Data collection