answers
_____ monitoring results gives organizations the capability to maintain
awareness of the risk being incurred, highlight the need to revisit other
steps in the risk management process, and initiate process improvement
activities as needed. Ans✓✓✓ Analyzing
A KPx is a summary of one or more KRIs. Ans✓✓✓ False
A threshold KPI is significant when an index falls into a set range.
Ans✓✓✓ True
All of the following are KPI types except: Ans✓✓✓ Esoteric
Change management ensures that similar systems have the same, or at
least similar, configurations. Ans✓✓✓ False
Change management is a process that ensures that changes are made
only after a review process. Ans✓✓✓ True
Configuration management is the same as change management.
Ans✓✓✓ False
, Continuous monitoring is necessary because security work is never
done. Ans✓✓✓ True
If there are three possible outcomes to an event, one of which has a
probability of 40% and will cost you $4000 and one of which has a
probability of 30% and which will cost you $1500, and another with a
probability of 30% that will cost you $2500, what is your expected loss?
Ans✓✓✓ 2800
In addition to deciding on appropriate monitoring activities across the
risk management tiers, organizations also decide how monitoring is to be
conducted (e.g., automated or manual approaches) and the frequency of
monitoring activities. Ans✓✓✓ True
In Information Security, KPIs measure the performance or health of
Information Security. Ans✓✓✓ True
Information security is a dynamic field because the risks fluctuate in a
complex and, hence, not entirely predictable manner. Ans✓✓✓ True
Key Performance Indicators monitor risk appetite. Ans✓✓✓ False
Key Risk Indicators should be tied to one or more Key Performance
Indexes. Ans✓✓✓ True