Safety & Risk Management Flashcards
7 cards from real SAC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Safety & Risk Management flashcards as text
Which type of fire suppression system is MOST appropriate for a data center to suppress fire without damaging equipment?
Answer: Clean agent suppression system (e.g., FM-200)
Clean agent systems such as FM-200 extinguish fires using chemical or inert gas agents that leave no residue and are safe for electronic equipment.
A system administrator is asked to implement a control ensuring that no single admin can both create a user account AND assign it administrative privileges. This is an example of:
Answer: Separation of duties
Separation of duties splits critical tasks between multiple individuals to prevent any one person from performing a complete high-risk transaction alone.
In patch management, what is the recommended FIRST step before deploying a critical security patch to production servers?
Answer: Test the patch in a staging environment that mirrors production
Testing patches in a staging environment first ensures compatibility and catches regressions before changes impact production workloads.
Which risk assessment approach uses numerical values and formulas to express risk in monetary terms?
Answer: Quantitative risk assessment
Quantitative risk assessment assigns numerical values to assets, threats, and probabilities to calculate monetary risk figures like ALE.
Which standard provides guidance specifically for Information Security Management Systems (ISMS) and is widely adopted in enterprise risk management?
Answer: ISO/IEC 27001
ISO/IEC 27001 is the international standard for establishing, implementing, maintaining, and continually improving an ISMS.
A UPS (Uninterruptible Power Supply) in a data center is classified as which type of physical security and safety control?
Answer: Preventive and compensating control
A UPS prevents data loss and system crashes during power failures (preventive) and compensates for the absence of utility power (compensating).
When conducting a vulnerability assessment, what distinguishes it from a penetration test?
Answer: A vulnerability assessment identifies and reports weaknesses without exploiting them, while a pen test actively exploits vulnerabilities
A vulnerability assessment enumerates and rates weaknesses without exploitation, whereas a penetration test attempts to actively exploit those vulnerabilities to confirm impact.