โ† All CySA+ Test Flashcard Decks

Risk Assessment Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment flashcards as text
  1. Which NIST publication provides the primary framework for federal agencies to conduct risk assessments?

    Answer: NIST SP 800-30

    NIST SP 800-30, 'Guide for Conducting Risk Assessments,' provides the process for identifying, estimating, and prioritizing risk to organizational operations.

  2. An organization's risk assessment reveals that a critical database server has no patch applied for a known critical vulnerability. The database is accessible only from inside the network. How should the risk be classified?

    Answer: Medium risk because internal controls partially offset the threat

    Network segmentation reduces but does not eliminate risk; internal threats and lateral movement make an unpatched critical system a medium-to-high concern requiring nuanced assessment.

  3. Which element of a Business Impact Analysis (BIA) identifies the maximum time a business process can be unavailable before causing unacceptable harm?

    Answer: Maximum Tolerable Downtime (MTD)

    Maximum Tolerable Downtime (MTD) defines the absolute longest period a business function can be offline before causing unacceptable consequences to the organization.

  4. A security analyst is reviewing risk assessment results and notices that two separate risks, when combined, create a significantly greater risk than either individually. This concept is called:

    Answer: Risk aggregation

    Risk aggregation occurs when multiple smaller risks combine to create a larger overall risk that exceeds the sum of its parts.

  5. During a risk assessment, a threat intelligence feed reports that a nation-state APT group is actively targeting organizations in your industry. How does this MOST directly affect your risk assessment?

    Answer: It increases the threat likelihood for relevant attack vectors

    Confirmed active targeting by a capable threat actor raises the probability (likelihood) that those specific attack vectors will be exploited in the near term.

  6. What is the PRIMARY purpose of conducting a risk assessment before implementing new security controls?

    Answer: To prioritize controls based on the greatest risk reduction per dollar spent

    Risk assessments enable organizations to allocate limited security resources to controls that provide the greatest reduction in overall risk relative to their cost.

  7. A penetration test report identifies a vulnerability that is technically severe but requires physical access to exploit. Which risk attribute does physical access requirement MOST affect?

    Answer: Likelihood

    Requiring physical access significantly reduces the probability of exploitation, directly lowering the likelihood component of the risk calculation.