← All CSC Flashcard Decks

Security Risk Management Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security Risk Management flashcards as text
  1. Which risk management concept refers to the idea that some level of risk always remains and can never be fully eliminated?

    Answer: Residual risk

    Residual risk acknowledges that even after all practical controls are implemented, some exposure remains because no control is 100% effective.

  2. A security consultant recommends a compensating control for a regulatory requirement the organization cannot currently meet. What is the PRIMARY purpose of a compensating control?

    Answer: To provide an alternative measure that achieves an equivalent level of protection

    A compensating control is an alternative safeguard that provides equivalent security when the original prescribed control cannot be implemented.

  3. Which scenario BEST exemplifies a risk avoidance strategy?

    Answer: Discontinuing an e-commerce feature that cannot be secured adequately

    Risk avoidance eliminates the risk entirely by ceasing the activity that creates it, such as removing a vulnerable feature from production.

  4. In the context of the NIST Cybersecurity Framework (CSF), which function is MOST closely aligned with the ongoing monitoring of security controls?

    Answer: Detect

    The Detect function covers the processes for continuous monitoring to identify cybersecurity events and anomalies in a timely manner.

  5. A CSC is advising on risk prioritization. Using a 5×5 risk matrix, a risk rated 4 (likelihood) × 5 (impact) equals a score of 20. How should this be prioritized relative to a risk scored 5 × 3 = 15?

    Answer: The 20-score risk should receive higher priority because it has a greater combined score

    A higher combined risk score on a risk matrix indicates greater overall risk exposure and warrants higher prioritization for treatment.

  6. Which term describes the process of reviewing and verifying that implemented security controls are operating effectively as intended?

    Answer: Control assessment

    Control assessment (also called control testing or auditing) evaluates whether implemented safeguards are functioning correctly and providing the intended risk reduction.

  7. A healthcare organization must comply with HIPAA Security Rule requirements. From a risk management perspective, how should the CSC frame HIPAA compliance?

    Answer: Compliance sets a minimum baseline; additional risk management is needed to address residual and evolving risks

    Regulatory compliance establishes a floor of required controls, but a mature risk management program goes beyond compliance to address the full threat landscape and residual risks.