Risk Flashcards

1
Q

What is Risk?

A

Possibility of a threat exploiting a vulnerability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is technical control?

A

Technology security i.e 802.11i

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is management control?

A

Risk/vulnerability assessment
Written security policy
Mandatory vacation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is operational control?

A

Change management/procedure

Ensure day-to-day operations comply with security policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a false positive?

A

IPS/IDS recoginises malicious trraffic when there isn’t

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a false negative?

A

IPS/IDS fails to recognise malicious traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is mandatory vacation?

A

Can reduce collusion and fraud of employees

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How is separation of duties more secure?

A

Developer creates application

Team implements software (i.e possible backdoor in software for dev)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is SLE?

A

Single loss expectancy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is ARO?

A

Annualised Rate of Occurrence

i.e 5 year failure 1/5 = 0.2 ARO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is ALE?

A

Annualised Loss Expectancy

ALE = SLE * ARO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a Software escrow

A

Source code of application available via provider company in event application is no longer supported

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is MTTR?

A

Mean Time to Restore

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is MTTF?

A

Mean Time to Failure

regarding non-repairable systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is MTBF?

A

Mean Time Between Failure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What entails risk acceptance?

A

Not paying for a countermeasure because the loss is less expensive

17
Q

What is risk transference?

A

Insurance from a 3rd party contractor for equipment servicing and replacement

18
Q

What is RTO?

A

Recovery Time Objective

19
Q

What is RPO?

A

Recovery Point Objective

retention period for restoration