← All CSC Flashcard Decks

Security Risk Management Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security Risk Management flashcards as text
  1. Which risk treatment option involves sharing the financial impact of a risk with a third party, such as through insurance?

    Answer: Risk transference

    Risk transference shifts the financial burden of a risk to another party, commonly through insurance or outsourcing contracts.

  2. A security consultant is performing a qualitative risk assessment. Which characteristic best describes this approach?

    Answer: Relies on subjective ratings such as High, Medium, and Low

    Qualitative risk assessments use descriptive scales and expert judgment rather than precise numerical monetary values.

  3. What does the term 'residual risk' refer to in security risk management?

    Answer: The risk that remains after controls have been implemented

    Residual risk is the remaining exposure after security controls have been applied to reduce the initial inherent risk.

  4. In a Business Impact Analysis (BIA), what is the PRIMARY purpose of identifying the Maximum Tolerable Downtime (MTD)?

    Answer: To determine how long a process can be disrupted before causing unacceptable harm

    MTD defines the longest period an organization can survive without a critical function before suffering irreversible damage, guiding recovery planning.

  5. Which formula correctly represents the calculation of Single Loss Expectancy (SLE)?

    Answer: SLE = Asset Value × Exposure Factor

    SLE is calculated by multiplying the asset value by the exposure factor, which represents the percentage of the asset lost in a single incident.

  6. A security consultant recommends implementing defense-in-depth. Which risk management principle does this strategy BEST support?

    Answer: Risk reduction by layering multiple compensating controls

    Defense-in-depth applies multiple overlapping security layers so that if one control fails, others continue to reduce risk.

  7. During a risk assessment, a consultant identifies a vulnerability with no known threat currently targeting it. What is the MOST appropriate action?

    Answer: Document it, monitor for emerging threats, and prioritize based on potential impact

    Even without an active threat, documenting and monitoring a vulnerability ensures it is addressed before it can be exploited if the threat landscape changes.