Risk Foundations
Terms & Definitions
Know the Organization
Assets & Information
Assess & Protect
100

CIA:DAD
Integrity:_________

What is Alteration?

100

A standardized identifier for a known cybersecurity vulnerability.

What is a CVE?

100

This is needed to understand why and how a business uses a given system.

What is mission/business purpose.

100

Hardware, software, data, and people can all fall into this category when they have value to an organization.

What are assets?

100

This assessment identifies weaknesses without attempting to exploit them.

What is a vulnerability assessment?

200

These two factors are combined to determine the level of risk.

What are likelihood/probability and impact?

200

This scoring system identifies the severity of a vulnerability.

What is CVSS?

200

This establishes how a system is set up right now, including hardware, software, and settings.

What is the current configuration?

200

Customer Social Security numbers and employee medical information would generally fall into this information classification.

What is protected or private information?

200

This type of testing attempts to exploit identified weaknesses.

What is penetration testing?

300

An organization decides to purchase cyber insurance to address the financial consequences of a risk. Which risk-handing strategy is it using?

What is risk transference?

300

This structure of cybersecurity safeguards helps organizations protect systems and data.

What are the CIS Controls?

300

This resource is used to document system configurations.

What are network/system diagrams?

300

An organization's product brochures or testimonials generally fall into this information classification.

What is public information?

300

Which is the technical control?

  • Acceptable Use Policy
  • Security token
  • Video camera

What is the security token?

400

An employee falls for a phishing email. Identify the exploit.

What is social engineering?

400

The risk remaining after controls have been implemented.

What is residual risk?

400

This process sets and maintains an approved, known state for systems and devices.

What is configuration management?

400

The amount required to purchase an equivalent new asset is its ________.

What is replacement value?

400

A vulnerability scanner reports that a server may be vulnerable to a known exploit. What has the analyst identified: a confirmed successful exploit or a potential vulnerability?

What is a potential vulnerability?

500

An employee falls for a phishing email. Identify the vulnerability.

What is lack of employee training or awareness?

500

This is a weakness that can be exploited, but it is not the event or actor that might exploit it.

What is a vulnerability?

500

This process controls an documents modifications to systems so that changes don't introduce new risk.

What is change management?

500

The replacement value of a server is $5,000, but restoring its software, configuration, and data adds another $8,000. What value should the organization use when planning for this loss?

What is recovery value?

500

A new security control consumes so many server resources that a critical application stops functioning. What important factor was overlooked?

What is operational impact of the control?