← All CWS Flashcard Decks

Risk Assessment & Mitigation Flashcards

7 cards from real CWS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Assessment & Mitigation flashcards as text
  1. Which wireless security control specifically addresses the risk of unauthorized devices joining the network by validating hardware identity before association?

    Answer: MAC address filtering

    MAC address filtering validates the hardware address of devices before allowing network association, though it is considered a weak control since MAC addresses can be spoofed.

  2. A risk assessment identifies that employees are using personal mobile hotspots to bypass corporate Wi-Fi monitoring. What is the PRIMARY security risk this creates?

    Answer: Corporate data traverses uncontrolled, unmonitored networks without DLP controls

    Personal hotspots create uncontrolled data paths where corporate sensitive data can leave the organization without passing through security controls like DLP, proxy filters, or monitoring systems.

  3. In a quantitative wireless risk assessment, which formula is used to calculate the Annual Loss Expectancy (ALE)?

    Answer: ALE = Single Loss Expectancy (SLE) × Annual Rate of Occurrence (ARO)

    ALE = SLE × ARO, where SLE is the financial loss per incident and ARO is how many times the incident is expected to occur per year, giving an annualized financial risk figure.

  4. A wireless network in a retail environment processes payment card data. Which compliance framework MOST directly governs the wireless security requirements in this scenario?

    Answer: PCI DSS (Payment Card Industry Data Security Standard)

    PCI DSS specifically addresses the protection of payment card data and includes detailed wireless security requirements for environments where cardholder data is processed or transmitted.

  5. An organization implements geo-fencing to restrict wireless network access. Which risk does this control PRIMARILY mitigate?

    Answer: Unauthorized access attempts from outside the defined geographic boundary

    Geo-fencing restricts network access based on physical location, preventing authentication or connectivity from devices outside the approved geographic area, reducing external threat exposure.

  6. During a wireless vulnerability assessment, an analyst finds that the RADIUS server uses a self-signed certificate. What specific attack risk does this create for EAP-PEAP authentication?

    Answer: Clients may be configured to accept any certificate, enabling rogue RADIUS server attacks

    When clients are configured to accept any certificate (common with self-signed certs), an attacker can deploy a rogue RADIUS server with their own certificate to intercept credentials during PEAP authentication.

  7. A risk treatment plan recommends 'risk transference' for the residual wireless security risk after controls are implemented. Which action BEST represents risk transference?

    Answer: Purchasing cyber liability insurance to cover potential wireless breach costs

    Risk transference shifts the financial burden of a risk to a third party, with cyber liability insurance being the classic example—it doesn't eliminate the risk but transfers the financial consequence.