FedVTE Fundamentals of Cyber Risk Management
Jeremiah
Terms in this set (52)
Which of the following families of controls Identification and Authentication
belong to the technical class of controls?
Which of the following is a management Accept
strategy for addressing risk?
Cyber risk management solutions are Technical, Physical, Administrative
typically done through which categories of
security controls?
There are agreements organizations may TRUE
enter into where one party is willing to
accept an amount of risk from another. That
transfer is a strategy for managing risk.
Which security principle is concerned with Integrity
the unauthorized modification of important
or sensitive information?
Simulating attack from a malicious source TRUE
could be part of penetration testing.
Which of the following is an example of a Security guard
physical control?
Incident response planning phase 1 Not B or C
(preparation) calls for:
The inputs (threat source motivation, threat Likelihood Determination
capacity, nature of vulnerability, and
current controls) will aid in generating
output used in which step of the NIST SP
risk assessment guidance?
The threat-source is motivated and Medium
capable, but controls are in place that may
impede successful exercise of the
vulnerability. Which likelihood rating does
FedVTE Fundamentals of Cyber Risk Management
this describe?
1/5
, 10/9/24, 3:47 PM
Which technical control places publicly De-militarized Zone
accessible servers in a special network
separated from the internal network?
Establishing the context and providing Risk Framing
common perspective on how organizations
manage risk is the goal of:
In the event of a major disaster, which of Hot
the following is a fully equipped alternate
site, requiring the shortest setup time to
resume full business operations?
Methods of response for managing risks Accept, Transfer, Mitigate, Avoid
are:
All of the following business assets have All of the above would be included
threats that would be included for
consideration as a part of threat analysis
EXCEPT:
The threat source is highly motivated and High
sufficiently capable, and controls to
prevent the vulnerability from being
exercised are ineffective. Which likelihood
rating does this describe?
Which tier of risk management is associated Not A or D
with Enterprise Architecture?
Which of the following security control Operational
class is for an information system and
primarily implemented and executed by
people?
OCTAVE FORTE uses the classic enterprise Executives
risk management toolset delivered in
OCTAVE Allegro but tailored to make it
more effective for whom to leverage the
information?
Which of the following strategies for Avoid
managing risk is described as: eliminating
the asset's exposure to risk, or elimination
of the asset itself?
NIST SP 800-30 defines risk as a measure of adverse impact and likelihood of occurrence
the extent to which an entity is threatened
by a potential circumstance or event, and
typically a function of:
A posted sign warning unauthorized Deterrent
access is prohibited and the presence of
security camera are what type of control?
A disaster recovery strategy where Self-service
organizations transfer business to another
of its branches until the event has resolved
is:
2/5
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller Denyss. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $11.99. You're not tied to anything after your purchase.