Security Risk Management Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Risk Management flashcards as text
Which of the following BEST describes the concept of 'inherent risk'?
Answer: The risk level that exists before any controls are implemented
Inherent risk is the raw, unmitigated level of risk present in an environment before any security controls are in place.
A CSC is asked to evaluate which assets require the most protection. Which criterion should carry the GREATEST weight in this determination?
Answer: The criticality and value of the asset to organizational operations
Asset criticality and business value are the primary drivers for prioritizing protection efforts in a risk-based security program.
What is the primary goal of a threat modeling exercise in the context of security risk management?
Answer: To identify potential threats, attack vectors, and prioritize mitigations early in design
Threat modeling systematically identifies threats and vulnerabilities during the design phase so that mitigations can be built in proactively.
Which risk assessment framework is commonly used by US federal agencies and contractors and is published by NIST?
Answer: RMF (SP 800-37)
NIST SP 800-37 defines the Risk Management Framework (RMF), which is mandatory for US federal information systems.
A security consultant discovers that two different business units use the same critical server but neither owns accountability for its security. This BEST illustrates which risk management problem?
Answer: Lack of asset ownership leading to security governance gaps
Without clearly assigned ownership, no one is accountable for protecting the asset, creating a governance gap that elevates risk.
In quantitative risk analysis, what does an Annualized Rate of Occurrence (ARO) of 0.25 indicate?
Answer: The threat is expected to occur once every four years
An ARO of 0.25 means the threat event is expected to occur 0.25 times per year, or approximately once every four years.
Which element distinguishes a risk register from a vulnerability assessment report?
Answer: A risk register tracks identified risks, their ratings, owners, and treatment status over time
A risk register is a living management document that records risks, their likelihood and impact ratings, responsible owners, and the status of treatment actions.