← All CCP Flashcard Decks

CCP Risk Management & Assessment Flashcards

6 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 CCP Risk Management & Assessment flashcards as text
  1. What is the standard formula for calculating risk in cybersecurity?

    Answer: Threat × Vulnerability × Asset Value

    Risk is commonly expressed as the product of threat likelihood, vulnerability severity, and asset value.

  2. Which risk treatment option involves shifting financial impact to a third party such as an insurer?

    Answer: Risk transference

    Risk transference moves the financial consequences of a risk event to another party, such as through cyber insurance.

  3. What is residual risk?

    Answer: Risk remaining after security controls have been applied

    Residual risk is the level of risk that persists after all security controls have been implemented.

  4. A qualitative risk assessment is best characterized by the use of:

    Answer: Descriptive ratings such as High, Medium, and Low

    Qualitative risk assessments use descriptive categories rather than precise numerical or financial values.

  5. What does Single Loss Expectancy (SLE) represent?

    Answer: The expected monetary loss from one occurrence of a specific risk event

    SLE is the estimated dollar loss associated with a single occurrence of a given risk event.

  6. Which document formally authorizes a system to operate while acknowledging its residual risks?

    Answer: Authorization to Operate (ATO)

    An Authorization to Operate (ATO) is issued by an authorizing official who accepts the residual risks of a system.