Study Guide Newest 2026 Questions and Correct
Detailed Answers Already Graded A+
Define the risk management process - CORRECT ANSWER-1. Identify assets
2. Identify threats
3. Assess vulnerabilities
4. Assess risks
5. Mitigate risks
Define the incident response process and its stages. - CORRECT ANSWER-
Preparation
Detection and analysis
Containment
Eradication
Recovery
Preparation in incident response - CORRECT ANSWER-creating policies and
procedures
,Detection in incident response - CORRECT ANSWER-Using tools and humans to
decide if an incident is an incident
Defense in Depth - CORRECT ANSWER-employing multiple layers of controls to
avoid a single point of failure
Identify types of controls to mitigate risk - CORRECT ANSWER-physical, logical,
administrative
Identify elements of risk management in policies and procedures. - CORRECT
ANSWER-Development of robust policies
Identification of emergent recent
Identify elements of internal weakness
Define the confidentiality in the CIA triad. - CORRECT ANSWER-Our ability to
protect data from those who are not authorized to view it.
Examples of confidentiality - CORRECT ANSWER-A patron using an ATM card
wants to keep their PIN number confidential.
An ATM owner wants to keep bank account numbers confidential.
, How can confidentiality be broken? - CORRECT ANSWER-Losing a laptop
An attacker gets access to info
A person can look over your shoulder
Define integrity in the CIA triad. - CORRECT ANSWER-The ability to prevent
people from changing your data and the ability to reverse unwanted changes.
How do you control integrity? - CORRECT ANSWER-Permissions restrict what
users can do (read, write, etc.)
Examples of integrity - CORRECT ANSWER-Data used by a doctor to make
medical decisions needs to be correct or the patient can die.
Define the availability in the CIA triad. - CORRECT ANSWER-Our data needs to
be accessible when we need it.
How can availability be broken? - CORRECT ANSWER-Loss of power,
application problems. If caused by an attacker, this is a Denial of Service attack.
Define information security. - CORRECT ANSWER-The protection of
information and information systems from unauthorized access, use, disclosure,