Risk Assessment Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Assessment flashcards as text
A CySA+ analyst is using the FAIR (Factor Analysis of Information Risk) model. What does FAIR primarily focus on?
Answer: Quantifying risk in financial terms using probability and magnitude
FAIR is a quantitative framework that models risk as a function of probable frequency and probable magnitude of loss events.
During threat modeling, which technique involves working backward from a defined adverse outcome to identify contributing causes?
Answer: Fault tree analysis
Fault tree analysis starts with an undesired top-level event and traces backward through logical branches to identify root causes and contributing failures.
An analyst discovers that a critical web application has a vulnerability with a CVSS base score of 9.1. Which factor would LOWER the environmental score for this system?
Answer: The system is not internet-facing and sits behind multiple firewalls
Environmental scores account for existing mitigating controls; being isolated behind firewalls reduces the exploitability in the specific environment.
Which risk concept describes the probability that a given threat will exploit a specific vulnerability within a defined time period?
Answer: Threat likelihood
Threat likelihood (also called probability) is the estimated chance that a threat event will occur and successfully exploit a vulnerability in a given timeframe.
A security team is assessing supply chain risk. Which control BEST reduces third-party vendor risk?
Answer: Conducting periodic third-party security assessments and audits
Periodic independent assessments and audits provide objective evidence of a vendor's security posture beyond self-attestation.
In a risk assessment, the Exposure Factor (EF) is defined as:
Answer: The percentage of an asset's value lost in a single threat event
Exposure Factor is the percentage of an asset's value that would be lost if a specific threat successfully exploits a vulnerability.
A risk analyst identifies that purchasing cyber liability insurance best addresses which risk treatment approach?
Answer: Risk transference
Cyber liability insurance transfers the financial consequences of a risk event to the insurance provider.