Safety & Risk Management Flashcards
7 cards from real SAC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Safety & Risk Management flashcards as text
What is the correct formula for calculating quantitative risk using Annual Loss Expectancy (ALE)?
Answer: ALE = SLE × ARO
ALE is calculated by multiplying Single Loss Expectancy (SLE) by Annual Rate of Occurrence (ARO) to express risk in annual monetary terms.
A system admin notices that a privileged account is being used outside of business hours repeatedly. Which security principle is MOST relevant for detecting this anomaly?
Answer: User behavior analytics / baseline monitoring
User behavior analytics establishes a baseline of normal activity and flags deviations, such as off-hours privileged account usage.
Which type of backup strategy captures only the data that has changed since the LAST FULL backup, regardless of incremental backups?
Answer: Differential backup
A differential backup copies all data changed since the last full backup, making restores faster than incremental but requiring more storage.
Which NIST framework function focuses on developing the organizational understanding to manage cybersecurity risk?
Answer: Identify
The 'Identify' function of the NIST Cybersecurity Framework focuses on understanding assets, risks, and governance to enable risk management.
A sysadmin is implementing controls for a server rack. Which physical security control serves as the FIRST line of defense against unauthorized physical access?
Answer: Biometric access controls on the data center door
Biometric access controls at the data center entry point prevent unauthorized individuals from ever reaching the server rack.
What term describes a vulnerability that is known to attackers but for which no vendor patch currently exists?
Answer: Zero-day vulnerability
A zero-day vulnerability is one that is unknown to or unpatched by the vendor, leaving systems exposed with no official fix available.
In OSHA regulations relevant to data center environments, which standard primarily governs electrical safety for workers servicing live equipment?
Answer: OSHA 29 CFR 1910.147 (Lockout/Tagout)
OSHA's Lockout/Tagout standard (1910.147) requires energy isolation procedures before servicing equipment to prevent accidental energization.