Cybersecurity Principles & Risk Management Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cybersecurity Principles & Risk Management flashcards as text
Which metric in quantitative risk analysis represents the expected monetary loss from a single occurrence of a threat event?
Answer: Single Loss Expectancy (SLE)
Single Loss Expectancy (SLE) is calculated as Asset Value multiplied by Exposure Factor, representing the cost of one occurrence of a specific threat.
What is the role of a risk owner in a cybersecurity risk management program?
Answer: Accept accountability for monitoring and managing an assigned risk
A risk owner is an individual accountable for ensuring that an identified risk is monitored, treated appropriately, and reported as needed.
Which concept describes the maximum level of risk an organization is prepared to accept in pursuit of its objectives?
Answer: Risk appetite
Risk appetite is the broad level of risk an organization is willing to accept before action is required, set by executive leadership and the board.
After applying security controls, what term describes the risk that remains?
Answer: Residual risk
Residual risk is the level of risk remaining after security controls and mitigations have been applied to the inherent risk.
Which framework is MOST commonly used by US federal agencies for risk management and security authorization?
Answer: NIST RMF (SP 800-37)
The NIST Risk Management Framework (RMF), described in SP 800-37, provides a structured process for integrating security into federal information systems and is mandated for US federal agencies.
An attacker intercepts a communication and secretly reads the data without altering it. Which security property is PRIMARILY violated?
Answer: Confidentiality
Confidentiality ensures that information is accessible only to those authorized to access it; passive eavesdropping attacks violate this property.
What is the MAIN difference between a policy and a standard in an information security governance framework?
Answer: Policies state high-level intent; standards define specific mandatory requirements
Policies express organizational intent and direction at a high level, while standards provide specific, mandatory requirements for implementing those policies.