โ† All 70-413 Exam Flashcard Decks

Risk Assessment & Management Flashcards

7 cards from real 70-413 Exam practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Management flashcards as text
  1. An organization uses a risk register to track identified risks. Which of the following fields is MOST important to include for effective risk monitoring over time?

    Answer: Risk owner and review date

    Assigning a risk owner and a review date ensures accountability and periodic reassessment of each risk in the register.

  2. Which threat modeling methodology focuses on identifying Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege threats?

    Answer: STRIDE

    STRIDE is Microsoft's threat modeling framework that categorizes threats into six types for structured analysis.

  3. During risk assessment for a Hyper-V deployment, you determine that the likelihood of a VM escape attack is very low but the impact would be catastrophic. How should you prioritize this risk?

    Answer: Prioritize it highly because catastrophic impact overrides low likelihood

    Catastrophic impact risks must be prioritized regardless of low likelihood because the potential damage is severe and irreversible.

  4. What is the purpose of a Business Impact Analysis (BIA) in the context of risk management?

    Answer: To identify critical business functions and the impact of disruptions to them

    A BIA identifies critical business processes and quantifies the impact of disruptions, informing recovery priorities and risk decisions.

  5. A Windows Server administrator discovers an unpatched vulnerability with a CVSS score of 9.8. The affected server has no internet exposure and sits behind multiple firewall layers. Which risk factor does this layered defense address?

    Answer: Threat likelihood/exploitability

    Network isolation reduces the likelihood that a threat actor can exploit the vulnerability, even though its severity remains high.

  6. An organization wants to assess the risk of deploying a new PKI infrastructure. Which assessment technique involves systematically mapping out how failures can propagate through a system?

    Answer: Fault tree analysis

    Fault tree analysis uses a top-down diagram to identify how combinations of failures can lead to a system-level adverse event.

  7. When performing risk assessment for a server deployment, 'residual risk' is best defined as:

    Answer: The risk that remains after security controls have been implemented

    Residual risk is the remaining level of risk after all planned security controls and mitigations have been implemented.