Security and Risk Management Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security and Risk Management flashcards as text
Which security planning document defines the acceptable level of loss that an organization is willing to tolerate?
Answer: Risk appetite statement
A risk appetite statement formally documents the amount and type of risk an organization is willing to accept in pursuit of its objectives.
The concept that no single person should have complete control over a critical process is known as:
Answer: Separation of duties
Separation of duties divides critical tasks among multiple individuals to prevent fraud and error by ensuring no one person can complete a harmful act alone.
Which US federal law specifically requires federal agencies to protect information systems and mandates FISMA compliance?
Answer: Federal Information Security Modernization Act (FISMA)
FISMA requires federal agencies to develop, document, and implement agency-wide programs to provide information security for their systems.
A qualitative risk assessment differs from a quantitative one in that it:
Answer: Relies on expert judgment and descriptive categories like High/Medium/Low
Qualitative risk assessments use subjective ratings and expert judgment rather than precise monetary calculations, making them faster but less precise.
Which term describes the remaining risk after safeguards and controls have been applied?
Answer: Residual risk
Residual risk is the leftover risk exposure after all planned countermeasures have been implemented and accepted by management.
Under GDPR, which role is responsible for giving instructions to the data processor and determining the purposes and means of processing personal data?
Answer: Data controller
The data controller determines why and how personal data is processed and bears primary legal responsibility for GDPR compliance.
Which threat modeling methodology focuses on identifying threats using attacker-centric categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?
Answer: STRIDE
STRIDE, developed by Microsoft, categorizes threats into six types and is widely used to systematically identify security threats during design.