_____________ is the likelihood that a threat will exploit a
vulnerability. Ans✓✓✓ Probability
A __________ is a common type of attack to deny service on Internet-
facing servers Ans✓✓✓ DDOS
A key step in managing risk is to first understand and manage the
source. Ans✓✓✓ True
A(n) ____________________ is an act against an asset that could result
in a loss. Ans✓✓✓ attack
According to the CIA triad, which of the following is a desirable
characteristic for computer security? Ans✓✓✓ Availability
All companies face the same set of vulnerabilities. Ans✓✓✓ False
All IT services and servers are equally critical. Ans✓✓✓ False
All systems have vulnerabilities. Ans✓✓✓ True
All vulnerabilities result in loss. Ans✓✓✓ False
, An asset has a value of 50 and 1 vulnerability. The vulnerability has a
probability of 1.0. There are no controls. It is estimated this information
is 90% accurate. What is the risk rating? Ans✓✓✓ 55
Another term for risk mitigation is _______. Ans✓✓✓ Risk reduction
Balanced security satisfies everyone. Ans✓✓✓ False
Data consistency is NOT a challenge when creating any type of Risk
Assessment. Ans✓✓✓ False
Data is often an organization's most valuable information asset, sensitive
data needs to be protected in which states? Ans✓✓✓ Data in Transit,
Data at Rest, Data in Process
Hardening a server makes the server more secure. Ans✓✓✓ True
Identify the true statement. Ans✓✓✓ Exploited vulnerabilities result in
losses.
In a qualitative Risk Analysis it is important to define value according to
the standard scale. Ans✓✓✓ True