Security and Risk Management Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security and Risk Management flashcards as text
Which risk treatment option involves sharing risk with a third party, such as through insurance or outsourcing?
Answer: Risk transference
Risk transference shifts the financial burden of a risk to another party, such as purchasing cyber liability insurance.
A company's ALE for a specific threat is $50,000 per year. A control costing $30,000 annually reduces the ALE to $10,000. What is the value of this control?
Answer: $20,000
Control value = (original ALE - residual ALE) - control cost = ($50,000 - $10,000) - $30,000 = $10,000, but the net risk reduction is $40,000 - $30,000 = $10,000; ALE reduction is $40,000 so value = $40,000 - $30,000 = $10,000.
Which framework provides a structured approach to integrating security and privacy into the system development lifecycle using a risk management hierarchy of organization, mission, and system levels?
Answer: NIST SP 800-37 RMF
NIST SP 800-37 describes the Risk Management Framework (RMF) with a three-tier hierarchy spanning organization, mission/business process, and information system levels.
Under the EU General Data Protection Regulation (GDPR), what is the maximum fine for the most serious violations?
Answer: €20 million or 4% of global annual turnover
GDPR Article 83(5) sets the maximum fine at €20 million or 4% of total worldwide annual turnover for the preceding year, whichever is higher.
Which principle requires that personnel are granted only the permissions necessary to perform their specific job functions?
Answer: Least privilege
Least privilege restricts user access rights to only what is required to perform authorized tasks, minimizing the attack surface.
A Business Impact Analysis (BIA) is primarily used to:
Answer: Determine the criticality and recovery priorities of business functions
A BIA identifies critical business functions, their dependencies, and establishes recovery time objectives (RTOs) and recovery point objectives (RPOs).
Which type of law imposes obligations on organizations to protect personal data and can result in civil penalties paid to affected individuals?
Answer: Tort law (civil law)
Tort law allows individuals harmed by negligent data handling to sue for damages, making it a key driver of privacy obligations for organizations.