Exam Prep Questions
-
Which of the following levels represent the military classification system?
-
Confidential, private, sensitive, and public
-
Top secret, secret, private, sensitive, and public
-
Top secret, confidential, private, sensitive, and unclassified
-
Top secret, secret, confidential, sensitive, and unclassified
-
This method of handling risk works by using a third party to absorb a portion of the risk.
-
Risk reduction
-
Risk transference
-
Risk acceptance
-
Risk rejection
-
You have been asked to calculate the annualized loss expectancy (ALE) for the following variables:
-
$9.00
-
$22.50
-
$10.00
-
$14.27
-
Place the following formulas in order:
-
ALE, residual risk, SLE, ARO
-
ALE, ARO, SLE, residual risk
-
ARO, SLE, ALE, residual risk
-
SLE, ARO, ALE, residual risk
-
The downside of performing this type of assessment is that you are not working with dollar values, so it is sometimes harder to communicate the results of the assessment to management.
-
Qualitative
-
Quantitative
-
Numeric mitigation
-
Red team
-
This category of control can include the logical mechanisms used to control access and authenticate users.
-
Administrative
-
Clerical
-
Technical
-
Physical
-
Which of the following formulas represents total risk?
-
Risk X Vulnerability X Asset value = Total risk
-
Threat X Vulnerability X Asset value = Total risk
-
Risk X Value/Countermeasure = Total risk
-
Threat - Vulnerability/Asset value = Total risk
-
Which of the following is a flaw, loophole, oversight, or error that makes an organization susceptible to attack or damage?
-
Risk
-
Vulnerability
-
Threat
-
Exploit
-
This is the most specific of security documents.
-
Procedures
-
Standards
-
Policies
-
Baselines
-
The last thing you want in an organization is that everyone is accountable but no one is responsible. Therefore, the data owner should be which of the following groups?
-
End users.
-
Technical managers.
-
Senior management.
-
Everyone is responsible; therefore, all groups are owners.
Single loss expectancy = $25
Exposure factor = .9
Annualized rate of occurrence = .4
Residual risk = $30