← All CSS Flashcard Decks

Security Risk Assessment & Analysis Flashcards

7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security Risk Assessment & Analysis flashcards as text
  1. Which risk assessment methodology uses probability and impact ratings to produce a numerical risk score?

    Answer: Quantitative risk assessment

    Quantitative risk assessment assigns numerical values to probability and impact to calculate a numeric risk score such as Annual Loss Expectancy (ALE).

  2. A security analyst calculates that a server has a 25% chance of being compromised each year with an asset value of $200,000 and an exposure factor of 40%. What is the Annual Loss Expectancy (ALE)?

    Answer: $20,000

    ALE = SLE × ARO; SLE = $200,000 × 40% = $80,000; ALE = $80,000 × 0.25 = $20,000.

  3. In risk management, what does the term 'threat vector' refer to?

    Answer: The path or means by which a threat actor gains access to a target

    A threat vector is the specific path, method, or route a threat actor uses to gain unauthorized access to a system or network.

  4. Which framework specifically provides a five-function model (Identify, Protect, Detect, Respond, Recover) for managing cybersecurity risk?

    Answer: NIST Cybersecurity Framework (CSF)

    The NIST Cybersecurity Framework (CSF) organizes cybersecurity activities around five core functions: Identify, Protect, Detect, Respond, and Recover.

  5. During a risk assessment, an organization identifies a vulnerability with no known exploit and no evidence of active threat actors targeting it. How should this risk be classified?

    Answer: Low — likelihood is minimal given no active exploitation

    Without an active threat actor or known exploit, the likelihood of exploitation is low, which lowers the overall risk rating even if the vulnerability is technically severe.

  6. What is the primary purpose of a Business Impact Analysis (BIA) in the context of risk assessment?

    Answer: To determine the financial and operational effects of disruption to critical business functions

    A BIA identifies critical business functions and quantifies the impact—financial, reputational, and operational—if those functions were disrupted.

  7. Which term describes the risk that remains after all planned security controls have been implemented?

    Answer: Residual risk

    Residual risk is the level of risk that persists after an organization has applied its security controls and mitigation measures.