โ† All CCP Flashcard Decks

CCP Risk Management & Assessment Flashcards

6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CCP Risk Management & Assessment flashcards as text
  1. A threat agent is best defined as:

    Answer: An entity capable of deliberately or accidentally exploiting a vulnerability

    A threat agent is the individual, group, or environmental force that has the potential to exploit a vulnerability.

  2. Which framework specifically guides U.S. federal agencies through a structured risk management process?

    Answer: NIST Risk Management Framework (RMF)

    The NIST RMF is mandatory for U.S. federal agencies and provides a structured process for managing information security risk.

  3. The term 'threat landscape' refers to:

    Answer: The complete range of potential threats facing an organization

    The threat landscape encompasses all known and emerging threats that an organization may face at a given point in time.

  4. Which process systematically identifies, documents, and prioritizes risks to organizational assets?

    Answer: Risk assessment

    Risk assessment is the structured process of identifying threats and vulnerabilities, then evaluating their likelihood and impact to prioritize treatment.

  5. What artifact produced during risk management records identified risks along with their likelihood, impact, and treatment plans?

    Answer: Risk Register

    A risk register is a living document that logs all identified risks, their ratings, and the actions planned or taken to address them.

  6. Risk appetite is best described as:

    Answer: The amount of risk an organization is willing to accept in pursuit of its objectives

    Risk appetite defines the level of risk an organization consciously accepts while pursuing its strategic and operational goals.