โ† All CSS Flashcard Decks

Security Risk Assessment & Analysis Flashcards

7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Risk Assessment & Analysis flashcards as text
  1. When performing a supply chain risk assessment, which practice helps an organization verify that third-party software has not been tampered with?

    Answer: Validating cryptographic hashes and digital signatures of software artifacts

    Cryptographic hash verification and digital signature validation confirm the integrity and authenticity of software, detecting any tampering in the supply chain.

  2. Which concept in risk assessment describes the point at which the cost of a control exceeds the value of the asset it protects?

    Answer: Cost-benefit analysis breakeven

    A cost-benefit analysis breakeven point occurs when control expenditure equals the risk reduction value, beyond which spending is economically unjustified.

  3. An organization is assessing risk for a new cloud deployment. Which cloud-specific risk factor relates to the organization's reduced visibility into the underlying infrastructure?

    Answer: Shared tenancy and lack of physical control

    In cloud environments, shared tenancy and the abstraction of physical infrastructure reduce the organization's visibility and control over the underlying hardware and hypervisor layer.

  4. A risk register entry states: 'Risk Owner: CISO; Risk Response: Mitigate; Control: MFA deployment; Review Date: Q3.' What is the primary purpose of assigning a risk owner?

    Answer: To designate accountability for monitoring and managing the risk

    A risk owner is accountable for ensuring the risk is appropriately monitored, treated, and reported, creating clear governance and follow-through.

  5. Which vulnerability assessment approach tests systems from outside the network perimeter without credentials, simulating an external attacker's perspective?

    Answer: Black-box external scan

    A black-box external scan is performed without credentials or insider knowledge, replicating what an unauthenticated external attacker would discover.

  6. During a risk assessment, an analyst determines that two separate low-probability risks, if they both occur simultaneously, would cause catastrophic damage. This is known as:

    Answer: Risk aggregation

    Risk aggregation recognizes that multiple individually low risks can combine to create a significantly higher cumulative or correlated risk exposure.

  7. Which of the following BEST describes the difference between a vulnerability assessment and a penetration test in the context of risk analysis?

    Answer: Vulnerability assessments identify and report weaknesses; penetration tests actively exploit them to demonstrate impact

    Vulnerability assessments enumerate and classify weaknesses, while penetration tests go further by safely exploiting those weaknesses to confirm real-world impact.