โ† All CSC Flashcard Decks

Security Risk Management Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Risk Management flashcards as text
  1. A security consultant is helping an organization decide between two controls: one eliminates the vulnerability entirely, the other reduces the likelihood of exploitation by 80%. Which terms BEST describe these options respectively?

    Answer: Risk elimination and risk reduction

    Eliminating a vulnerability is risk elimination (a form of avoidance), while reducing exploit likelihood by 80% is risk reduction (mitigation).

  2. Which of the following statements about risk appetite versus risk tolerance is MOST accurate?

    Answer: Risk appetite is the broad strategic willingness to accept risk; risk tolerance is the acceptable deviation from that appetite

    Risk appetite defines the overall level of risk an organization is willing to pursue, while risk tolerance specifies the acceptable variance or deviation around that appetite.

  3. During a vendor risk assessment, which factor MOST increases third-party risk exposure for an organization?

    Answer: The vendor has access to sensitive customer data and operates with minimal security oversight

    Third-party risk peaks when vendors can access sensitive data and lack adequate security controls, creating a potential pathway for breaches.

  4. A CSC is reviewing an organization's risk management program and finds that identified risks have not been reassessed in three years. What is the PRIMARY concern?

    Answer: The risk register may not reflect the current threat landscape and changed business environment

    Risk assessments must be conducted periodically because threats, vulnerabilities, and business contexts evolve, making outdated assessments unreliable for decision-making.

  5. Which control type is BEST suited to detect unauthorized access attempts after they occur?

    Answer: Detective control

    Detective controls, such as intrusion detection systems and audit log reviews, identify and alert on security incidents after they have taken place.

  6. An organization accepts a risk because the cost of mitigation exceeds the potential loss. This decision should be formally documented in which artifact?

    Answer: Risk acceptance memorandum signed by appropriate management

    Formal risk acceptance requires a signed acknowledgment from management with authority over the risk, ensuring accountability and audit trail.

  7. What is the relationship between a threat and a vulnerability in security risk management?

    Answer: A threat is an actor or event that may exploit a vulnerability to cause harm

    A threat is a potential cause of harm (e.g., an attacker or natural disaster), while a vulnerability is a weakness that the threat can exploit.