QUESTION 1
1. Why should the people on the RA team be different from the people responsible for correcting deficiencies?
to avoid potential losses
to increase profitability
to avoid conflicts of interest
to increase survivability
0.10000 points
QUESTION 2
1. If you know an SLE is $100 and the associated ARO is 5 months, then what is the ALE?
$105
$20
20 months
$500
0.10000 points
QUESTION 3
1. Change management is a process that ensures that changes are made only after a review process.
True
False
0.10000 points
QUESTION 4
1. When should you perform a risk assessment?
when mitigating a threat
when eliminating a threat
periodically
continuously
0.10000 points
QUESTION 5
1. What is a hardware lock?
A type of firewall
A type of antivirus software
A type of RA
A type of metal cable
0.10000 points
QUESTION 6
1. Data consistency is not a challenge when creating any type of RA.
True
False
0.10000 points
QUESTION 7
1. The primary benefit of the Delphi Method is that it allows individuals to freely share their opinions without pressure.
True
False
0.10000 points
QUESTION 8
1. When using the Delphi Method, it is best to collect data in a meeting.
True
False
0.10000 points
QUESTION 9
1. A(n) ___________________ is performed to identify the most serious risks, help you manage risks, and identify the best methods to control risks.
RA
CBA
POAM
SOX
0.10000 points
QUESTION 10
1. An RA team should focus both on critical areas and on what management might consider important.
True
False
0.10000 points
QUESTION 11
1. Residual risk is any risk that remains after management has decided to implement controls.
True
False
0.10000 points
QUESTION 12
1. The first section of a qualitative RA attempts to prioritize risk. The second section of a qualitative RA evaluates the effectiveness of controls.
True
False
0.10000 points
QUESTION 13
1. RAs are simpler to complete than risk management plans, because risk management plans are continuous processes while RAs are simple point-in-time documents that can easily be completed in a single sitting.
True
False
0.10000 points
QUESTION 14
1. You run a bank and wish to update your physical security at each branch of your bank and to update the technological security of the bank’s private financial data. What is the best way to determine whether physical security or technological security has a higher priority of protection?
CBAs
POAMs
CVEs
RAs
0.10000 points
QUESTION 15
1. _____________ is the likelihood that a threat will exploit a vulnerability.
Probability
Impact
Risk
Assessment
0.10000 points
QUESTION 16
1. A risk assessment is the same as a risk management program.
True
False
0.10000 points
QUESTION 17
1. Qualitative RAs determine the level of risk based on the __________ and _________ of risk.
impact, threat
probability, impact
threat, probability
threat, dollar value
0.10000 points
QUESTION 18
1. ____________ assessments are objective, while ___________ assessments are subjective.
Quantitative, qualitative
Risk, threat
Qualitative, quantitative
Threat, risk
0.10000 points
QUESTION 19
1. The value of an assessment is only as valuable as the expertise of the experts.
True
False
0.10000 points
QUESTION 20
1. A (n) __________ is a common type of attack on Internet-facing servers.
firewall
DMZ
database server
SQL injection
0.10000 points
QUESTION 1
1. Configuration management ensures that similar systems have the same, or at least similar, configurations.
True
False
0.10000 points
QUESTION 2
1. Addresses ______________ are automatically marked as spam.
on a white list
from a DMZ
on a blacklist
in an address book
0.10000 points
QUESTION 3
1. The _____________ define(s) what the system does.
mission of the system
RA
operational characteristics
previous findings
0.10000 points
QUESTION 4
1. What may occur if you do NOT include the scope of the RA when defining it?
attacks
exploited threats
losses
missed deadlines
0.10000 points
QUESTION 5
1. What might happen if you began evaluating threats before defining the current operational characteristics?
improper conclusions
previous findings rendered useless
missed deadlines
cost overruns
0.10000 points
QUESTION 6
1. The main benefit of a vulnerability assessment is that hackers cannot perform the same steps as people performing the assessment.
True
False
0.10000 points
QUESTION 7
1. What is NOT a classification of data?
risk
proprietary
private
public
0.10000 points
QUESTION 8
1. An exploit assessment is also known as a(n) ___________.
exploit list
penetration test
vulnerability assessment
threat survey
0.10000 points
QUESTION 9
1. What is a whitelist?
a list of e-mail addresses or domains automatically marked as spam
a list of e-mail addresses targeted in a phishing scam
a list of approved e-mail addresses or domains
a list of rejected e-mail domains
0.10000 points
QUESTION 10
1. __________ define(s) how the system operates in your environment.
The mission of the system
Operational characteristics
RAs
Previous findings
0.10000 points
QUESTION 11
1. The two primary steps you need to complete before progressing with an RA are defining the assessment and reviewing previous findings.
True
False
0.10000 points
QUESTION 12
1. Compared to the operational characteristics of the system, the mission of the system is easy to define.
True
False
0.10000 points
QUESTION 13
1. All of the following are reasons why configuration management is an important risk management process, EXCEPT:
It makes configuration more efficient.
It reduces unintended outages.
It is easier to maintain systems collectively.
It is easier to evaluate risks.
0.10000 points
QUESTION 14
1. What is an example of a Group Policy?
end user license agreement
privacy policy
password policy
nondisclosure agreement
0.10000 points
QUESTION 15
1. ______________ refers to how responsibilities are assigned.
Operational characteristics
Management operations
Configuration management
Management structure
0.10000 points
QUESTION 16
1. All systems have vulnerabilities.
True
False
0.10000 points
QUESTION 17
1. The two primary areas you will often focus on when describing the system or process are the assessment and previous findings.
True
False
0.10000 points
QUESTION 18
1. Small organizations with fewer resources will need to separate RAs, but larger and better equipped organizations have streamlined the process so that only one RA is needed for all their systems.
True
False
0.10000 points
QUESTION 19
1. Companies with higher turnover rates have fewer problems than companies with lower turnover rates.
True
False
0.10000 points
QUESTION 20
1. Change management ensures that similar systems have the same, or at least similar, configurations.
True
False
0.10000 points
Click Save and Submit to save and submit. Click Save All Answers to save all answers.