Lecture 14 Flashcards

1
Q

What is a risk in the context of information security?

A

Risk is the potential for loss, expressed as the probability that a threat will exploit a vulnerability with a harmful result.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the primary goal of risk management?

A

To reduce risk to an acceptable level.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the key components of risk analysis?

A
  • Identifying threats
  • Evaluating likelihood
  • Assessing damage cost
  • Analyzing countermeasure costs
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Define ‘asset’ in risk management.

A

A system resource that has value and requires protection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a vulnerability?

A

A weakness in an asset’s design, implementation, or management that could be exploited.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How do you calculate risk in quantitative risk analysis?

A

Risk = Probability of Threat × Impact Cost

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is qualitative risk analysis?

A

A risk analysis approach based on expert judgment rather than numerical values.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the four risk treatment strategies?

A
  • Risk acceptance
  • Risk avoidance
  • Risk transfer
  • Risk reduction
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the ‘Defense in Depth’ strategy?

A

A security strategy using multiple layers of defense mechanisms.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Name the three main security goals.

A
  • Confidentiality
  • Integrity
  • Availability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are examples of security controls?

A
  • Encryption
  • Access controls
  • Firewalls
  • Intrusion detection systems
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is non-repudiation in security?

A

Assurance that an entity cannot deny having performed an action.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly