Basic Risk Concepts Flashcards

1
Q

What is the definition of a Threat?

A

is any circumstance or event that has the potential

to compromise confidentiality, integrity, or availability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Risk is the possibility or likelihood of…

A

threat exploiting a vulnerability

resulting in a loss

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 3 types of controls that describe HOW the control is implemented?

A

Technical, Administrative and Physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

organizational policies and guidelines are used to implement what kind of control?

A

administrative controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

operational controls, which are a form of admin control, ensure the day-to-day operations of an organization comply with the org’s overall security plan - true or false?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Account disablement, security guards and hardening are examples of what type of control?

A

Preventative

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

backup and system recovery is a type of what control?

A

Corrective. Because it reverses the data loss

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

what control is an alternative control used instead of a primary control?

A

compensating control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the 4 control types that describe the GOAL of the control

A

Deterrent
Detective
Corrective
Preventative

How well did you know this?
1
Not at all
2
3
4
5
Perfectly