โ† All CySA+ Test Flashcard Decks

Risk Assessment Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment flashcards as text
  1. A CySA+ analyst is using the FAIR (Factor Analysis of Information Risk) model. What does FAIR primarily focus on?

    Answer: Quantifying risk in financial terms using probability and magnitude

    FAIR is a quantitative framework that models risk as a function of probable frequency and probable magnitude of loss events.

  2. During threat modeling, which technique involves working backward from a defined adverse outcome to identify contributing causes?

    Answer: Fault tree analysis

    Fault tree analysis starts with an undesired top-level event and traces backward through logical branches to identify root causes and contributing failures.

  3. An analyst discovers that a critical web application has a vulnerability with a CVSS base score of 9.1. Which factor would LOWER the environmental score for this system?

    Answer: The system is not internet-facing and sits behind multiple firewalls

    Environmental scores account for existing mitigating controls; being isolated behind firewalls reduces the exploitability in the specific environment.

  4. Which risk concept describes the probability that a given threat will exploit a specific vulnerability within a defined time period?

    Answer: Threat likelihood

    Threat likelihood (also called probability) is the estimated chance that a threat event will occur and successfully exploit a vulnerability in a given timeframe.

  5. A security team is assessing supply chain risk. Which control BEST reduces third-party vendor risk?

    Answer: Conducting periodic third-party security assessments and audits

    Periodic independent assessments and audits provide objective evidence of a vendor's security posture beyond self-attestation.

  6. In a risk assessment, the Exposure Factor (EF) is defined as:

    Answer: The percentage of an asset's value lost in a single threat event

    Exposure Factor is the percentage of an asset's value that would be lost if a specific threat successfully exploits a vulnerability.

  7. A risk analyst identifies that purchasing cyber liability insurance best addresses which risk treatment approach?

    Answer: Risk transference

    Cyber liability insurance transfers the financial consequences of a risk event to the insurance provider.