Security Risk Assessment & Analysis Flashcards
7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security Risk Assessment & Analysis flashcards as text
Which of the following best describes 'threat intelligence' in the context of risk assessment?
Answer: Evidence-based knowledge about existing or emerging threats used to inform risk decisions
Threat intelligence is actionable, evidence-based knowledge—about adversaries, their capabilities, and tactics—that enhances the accuracy of risk assessments.
An organization maps its assets, threats, and vulnerabilities and then plots each risk on a grid with 'Likelihood' on one axis and 'Impact' on the other. This tool is called a:
Answer: Risk heat map (risk matrix)
A risk heat map (or risk matrix) visually plots risks by likelihood and impact, using color coding to highlight the most critical risks.
The FAIR (Factor Analysis of Information Risk) model primarily decomposes risk into which two top-level factors?
Answer: Loss Event Frequency and Loss Magnitude
FAIR decomposes risk into Loss Event Frequency (how often a loss event occurs) and Loss Magnitude (how much value is lost per event).
Which of the following is an example of a 'secondary risk'?
Answer: A risk introduced by the implementation of a risk treatment plan itself
Secondary risks arise as a direct result of implementing a risk response, such as introducing new dependencies or failure points through a mitigation control.
During scoping a risk assessment, an analyst applies the concept of 'risk appetite' vs. 'risk tolerance.' What does risk tolerance define?
Answer: The acceptable deviation from the risk appetite that the organization can withstand
Risk tolerance is the acceptable variation or deviation around the risk appetite level—it defines the boundaries within which the organization can operate.
A security team uses attack trees to support risk analysis. What is the root node of an attack tree?
Answer: The goal or objective the attacker is trying to achieve
The root node of an attack tree represents the attacker's ultimate goal, with child nodes representing the conditions or sub-goals needed to achieve it.
Which standard provides guidance specifically on information security risk management processes and is part of the ISO/IEC 27000 family?
Answer: ISO/IEC 27005
ISO/IEC 27005 provides guidelines for information security risk management, supporting the implementation of an ISMS as defined in ISO/IEC 27001.