โ† All CSC Flashcard Decks

Threat Assessment & Risk Analysis Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Threat Assessment & Risk Analysis flashcards as text
  1. A CSC is evaluating a cloud provider's shared responsibility model for risk allocation. Who is primarily responsible for data classification in an IaaS environment?

    Answer: The customer/tenant organization

    In IaaS, the customer retains full responsibility for data classification, access control, and application security above the infrastructure layer.

  2. Which threat intelligence framework uses a diamond model to describe the relationships between adversary, capability, infrastructure, and victim?

    Answer: The Diamond Model of Intrusion Analysis

    The Diamond Model of Intrusion Analysis structures threat intelligence around four core features: adversary, capability, infrastructure, and victim.

  3. A security consultant is helping a healthcare organization prioritize risks. Under HIPAA, which category of data breach triggers mandatory notification?

    Answer: Unauthorized acquisition, access, use, or disclosure of unsecured protected health information (PHI)

    HIPAA Breach Notification Rule requires notification when unsecured PHI is acquired, accessed, used, or disclosed in an impermissible manner.

  4. In a risk heat map, a risk plotted in the upper-right quadrant indicates which condition?

    Answer: High likelihood and high impact

    In standard risk heat maps, the upper-right quadrant represents the highest combined likelihood and impact, indicating critical priority risks.

  5. A CSC recommends a threat hunting program to a client. What distinguishes threat hunting from traditional security monitoring?

    Answer: Threat hunting is a proactive, hypothesis-driven search for threats that have evaded automated detection

    Threat hunting proactively searches for threats using analyst hypotheses and behavioral analytics, targeting adversaries that bypassed automated controls.

  6. Which standard provides a risk management framework specifically designed for information security, aligning with ISO 31000 principles?

    Answer: ISO/IEC 27005

    ISO/IEC 27005 provides guidelines for information security risk management and is explicitly designed to align with ISO 31000's generic risk management principles.

  7. A CSC conducts a vulnerability assessment and finds a critical unpatched server. The server processes financial transactions and has no network segmentation. Using risk prioritization, what combination of factors makes this a top-priority finding?

    Answer: High asset criticality, high exploitability, and absence of compensating controls

    Maximum risk priority occurs when a critical asset is highly exploitable and lacks compensating controls, combining high impact, high likelihood, and no mitigation.