← All CySA+ Test Flashcard Decks

Risk Assessment Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Assessment flashcards as text
  1. Which risk assessment approach is MOST appropriate when an organization lacks historical loss data needed for financial calculations?

    Answer: Qualitative risk assessment using a risk matrix

    Qualitative risk assessment uses expert judgment and descriptive scales instead of financial data, making it suitable when historical loss data is unavailable.

  2. An analyst uses the Delphi technique during a risk assessment. What is the PRIMARY characteristic of this method?

    Answer: Anonymous iterative expert consensus building

    The Delphi technique gathers anonymous input from multiple experts across multiple rounds until consensus is reached, reducing groupthink bias.

  3. A CySA+ analyst is evaluating risk for a cloud-hosted application. Which cloud-specific risk factor requires unique consideration compared to on-premises systems?

    Answer: Shared responsibility model ambiguity

    The shared responsibility model creates unique risk when organizations are unclear about which security tasks belong to the cloud provider versus the customer.

  4. An organization is assessing third-party risk for a SaaS vendor that processes sensitive customer data. Which assessment activity provides the MOST assurance about the vendor's security posture?

    Answer: Requesting and reviewing SOC 2 Type II audit reports

    A SOC 2 Type II report provides independent auditor verification that security controls were effective over an extended observation period, not just at a single point in time.

  5. Which metric in CVSS v3.1 specifically measures the level of access an attacker must already have before exploiting a vulnerability?

    Answer: Privileges Required (PR)

    Privileges Required (PR) indicates whether the attacker needs no, low, or high privilege levels on the target system prior to exploitation.

  6. A risk assessment identifies that an aging legacy system cannot be patched due to vendor end-of-life. The system must remain operational. Which control strategy BEST addresses this situation?

    Answer: Apply compensating controls such as network isolation and enhanced monitoring

    When patching is impossible and decommissioning is not an option, compensating controls like network segmentation and increased monitoring reduce exploitability and detection time.

  7. Which of the following BEST describes the relationship between vulnerability, threat, and risk?

    Answer: Risk arises when a threat exploits a vulnerability to impact an asset

    Risk exists at the intersection of a threat (capable actor or event), a vulnerability (exploitable weakness), and an asset with value — all three components must be present.