Risk Assessment & Management Flashcards
7 cards from real 70-413 Exam practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
You are calculating Annual Loss Expectancy (ALE) for a server asset worth $200,000. The Exposure Factor is 50% and the Annualized Rate of Occurrence is 0.1. What is the ALE?
Answer: $10,000
ALE = SLE × ARO = ($200,000 × 0.5) × 0.1 = $100,000 × 0.1 = $10,000.
Which risk management framework is specifically designed for IT systems and is published by NIST, making it widely used in US federal environments?
Answer: NIST SP 800-30
NIST SP 800-30 provides guidelines for conducting risk assessments of federal information systems and organizations.
An attacker gains access to a server through a known vulnerability that was already patched in a tested update. The patch was not deployed because the change management window hadn't opened. What risk category does this represent?
Answer: Operational/process risk
Failure to deploy a known patch due to a process delay is an operational risk, not a technical one — the fix existed but processes prevented its application.
During a risk assessment workshop, stakeholders disagree about the probability of a particular threat. Which qualitative technique helps build consensus by iterating anonymous expert opinions until convergence?
Answer: Delphi technique
The Delphi technique uses anonymous iterative rounds of expert input to reach consensus while avoiding groupthink.
A risk assessment identifies that an unauthorized admin could disable Windows Firewall on critical servers. Implementing a Group Policy that prevents firewall modification is an example of which control type?
Answer: Preventive control
A Group Policy that prevents disabling the firewall proactively blocks the action from occurring, making it a preventive control.
In the context of 70-413 designing a server infrastructure, which Hyper-V feature helps mitigate the risk of unauthorized VM sprawl and resource exhaustion?
Answer: VM resource metering and quotas
VM resource metering and quotas enforce limits on CPU, memory, and storage per VM, preventing any single VM from exhausting shared resources.
A risk assessment recommends encrypting backup tapes stored off-site. An executive decides the cost outweighs the benefit and documents this decision. This is an example of:
Answer: Risk acceptance
Formally deciding not to implement a control and documenting the decision is risk acceptance of the identified residual risk.