Threat Identification & Risk Management Flashcards
7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Threat Identification & Risk Management flashcards as text
A security investigator is performing a risk assessment for a retail chain. Which asset would typically be assigned the HIGHEST value?
Answer: Customer payment card data
Customer payment card data carries the highest value due to regulatory requirements, financial exposure, and reputational damage if compromised.
What is the purpose of a 'red team' exercise in threat identification?
Answer: Simulate adversarial attacks to identify exploitable vulnerabilities
A red team simulates real-world adversary tactics to uncover vulnerabilities before actual attackers can exploit them.
Which concept describes the practice of reducing a system's attack surface by disabling unnecessary services and features?
Answer: Hardening
Hardening involves removing or disabling non-essential services, accounts, and features to reduce the number of exploitable entry points.
An organization experiences multiple minor security incidents over six months with no formal documentation. This represents a failure in:
Answer: Incident recording and trending analysis
Failing to document incidents prevents trend analysis, which is critical for identifying emerging or escalating threats.
In risk management terminology, what does 'ALE' stand for and represent?
Answer: Annual Loss Expectancy — estimated yearly financial loss from a specific risk
Annual Loss Expectancy (ALE) is calculated as Single Loss Expectancy multiplied by Annualized Rate of Occurrence, representing expected yearly loss.
A security threat that is publicly known but for which no patch or countermeasure yet exists is called:
Answer: Zero-day vulnerability
A zero-day vulnerability is an exploitable flaw that is publicly known or actively exploited before a fix is available.
During a risk assessment, which step comes IMMEDIATELY after identifying threats and vulnerabilities?
Answer: Analyzing and evaluating the risk
After identifying threats and vulnerabilities, the next step is to analyze and evaluate the risk to determine its likelihood and potential impact.