Study. uk . com
  1. Home
  2. All questions
  3. Risk management

CompTIA Security+ study material: Risk management

130 questions of the 611 in the CompTIA Security+ quiz. Each opens with its answer, the reasoning and where that is written down.

Challenge yourself on this topic → Study as cards

The questions

  1. 1. A security team rates a finding as high risk purely because the potential loss would be severe, without considering how plausible the event is. Which part of the standard definition of risk have they left out?
  2. 2. Which two of the following are risk factors in the NIST risk model? Choose two.
  3. 3. A power supply fails and takes a database offline. Under the standard definition, how should this be classified?
  4. 4. Which two of the following are recognised categories of threat source? Choose two.
  5. 5. An analyst argues that because a provisioning server outage was traced to an administrator's mistake, denial of service can be removed from the risk register for that server. Why is this reasoning wrong?
  6. 6. After an organisation deploys strong controls on its public web tier, attackers begin targeting a smaller partner instead. What is this behaviour called?
  7. 7. An assessment notes that the organisation has no central asset inventory, which makes many threat events more likely to succeed. In risk-model terms, what has been described?
  8. 8. At which tier of the risk management hierarchy are decisions about the organisation-wide risk management strategy made?
  9. 9. Before running its first formal risk assessment, an organisation documents its assumptions, constraints, priorities and tolerance. Which activity is this?
  10. 10. A manager decides, during a finding review, how much risk the organisation is willing to accept. What is wrong with deciding it at that point?
  11. 11. A threat report describes how a group gains access, moves laterally and exfiltrates data, without naming any specific tool. What is being described?
  12. 12. Which sequence correctly lists the steps of the Risk Management Framework?
  13. 13. Which RMF step determines which control baseline the system will start from?
  14. 14. Who makes the decision to accept a system's residual risk and issue an authorisation to operate?
  15. 15. An organisation wants to move from three-yearly reauthorisation to ongoing authorisation. Which capability makes that possible?
  16. 16. Agency B accepts Agency A's existing assessment evidence for a shared service instead of repeating the assessment. What is this practice called?
  17. 17. A data centre's physical security controls are implemented once and relied on by every system hosted there. What are these called, and who is accountable for them?
  18. 18. A team draws a system's authorisation boundary very narrowly to reduce assessment effort. What is the main consequence?
  19. 19. An executive asks why the Cybersecurity Framework does not tell them which products to buy. What is the correct explanation?
  20. 20. Which two concerns were raised to first-class prominence in version 2.0 of the Cybersecurity Framework? Choose two.
  21. 21. How is the Cybersecurity Framework Core structured?
  22. 22. An organisation builds a current Profile and a target Profile using the Cybersecurity Framework. What does comparing them produce?
  23. 23. A consultant reports that the organisation "is at Tier 2" as a single maturity score for its whole security programme. Why is this a misuse of Tiers?
  24. 24. Why does the Cybersecurity Framework encourage managing cybersecurity risk alongside financial, privacy, supply chain and reputational risk?
  25. 25. An asset is worth $200,000. A fire would destroy half of it, and fires of that kind are expected once every ten years. What is the annualised loss expectancy?
  26. 26. Which two values are multiplied to produce a single loss expectancy?
  27. 27. An organisation has no reliable loss data for a new class of risk and needs a ranking quickly. Which approach fits, and what is its main limitation?
  28. 28. A vendor will not patch a flaw in a product the organisation uses. Which two of the following are recognised risk responses in this situation? Choose two.
  29. 29. After buying cyber insurance, a director states that the breach risk now belongs to the insurer. What is wrong with this claim?
  30. 30. Which quantity does an authorising official actually accept when granting an authorisation to operate?
  31. 31. What does a risk register record beyond the description of each risk?
  32. 32. How do risk appetite and risk tolerance differ?
  33. 33. Which analysis determines what a disruption would cost over time and which processes must be recovered first?
  34. 34. A service may be unavailable for at most four hours, and at most fifteen minutes of transactions may be lost. Which objectives do these two statements set?
  35. 35. A business states that beyond 48 hours of downtime the company would not survive. The recovery time objective is then set at 48 hours. What is wrong?
  36. 36. Which three problems does cybersecurity supply chain risk management address in products and services an organisation acquires?
  37. 37. An organisation wants to impose security requirements on a SaaS provider. When does it have the most leverage to do so?
  38. 38. After a supplier incident, an organisation asks to review the supplier's security evidence and is refused. What should have been in place?
  39. 39. Which agreement states the availability a provider commits to and the remedy if it is missed?
  40. 40. An organisation signs many small engagements with one consultancy and wants to avoid renegotiating liability and security terms each time. Which instrument achieves this?
  41. 41. Which two items must the rules of engagement for a penetration test establish? Choose two.
  42. 42. An assessor reviews configuration files, policies and logs without sending any traffic to the system. Which activity is this?
  43. 43. A manager reports to the board that a vulnerability scan "proved the systems can be breached". Why is that claim unsupported?
  44. 44. A customer requires assurance that carries weight with its own regulator. Which type of audit best meets that need?
  45. 45. An organisation passes its regulatory audit and is breached three months later. Which statement best explains how both can be true?
  46. 46. How do due diligence and due care differ?
  47. 47. A document states "all servers must use disk encryption approved by the security team" and lists the approved algorithms. Which governance artefact is this?
  48. 48. Which governance artefact offers recommended practice that staff are not obliged to follow?
  49. 49. An employee is dismissed for misusing company systems and challenges the decision. Which document most directly supports the organisation's position?
  50. 50. Who decides a data set's classification and who may access it?
  51. 51. A security team wants to know whether awareness training has changed behaviour rather than recall. Which measure fits best?
  52. 52. Why do developers and system administrators receive different security training from general staff?
  53. 53. A user who clicked a phishing link waits two days before telling anyone, fearing discipline. Which change most directly reduces this delay?
  54. 54. A team uses a vulnerability's CVSS score directly as its risk rating. Which factor does CVSS deliberately exclude that they must add themselves?
  55. 55. A vulnerability's base score is taken straight from a public feed and used to rank remediation. What assumption is being carried in unexamined?
  56. 56. A report labels a score CVSS-BTE. What does the label tell the reader?
  57. 57. Two flaws both score 8.8. One appears in the Known Exploited Vulnerabilities catalog. Which should be remediated first and why?
  58. 58. Which two conditions must be met before a vulnerability is added to the Known Exploited Vulnerabilities catalog? Choose two.
  59. 59. Why does the Known Exploited Vulnerabilities catalog read more like a directive than an advisory list?
  60. 60. Which set correctly lists the four Traffic Light Protocol labels?
  61. 61. An analyst receives a report marked TLP:AMBER. Who may they share it with?
  62. 62. Which TLP label means the information may go no further than the individuals who received it?
  63. 63. A team proposes replacing its data classification scheme with TLP labels. Why is that a mistake?
  64. 64. An analyst needs to share TLP:GREEN information with a public blog audience. What must they do?
  65. 65. A researcher finds a flaw in a company's product and cannot locate any way to report it. Which control would have prevented this situation?
  66. 66. Which element of a vulnerability disclosure policy most directly encourages a good-faith researcher to report rather than stay silent?
  67. 67. A company with a two-person security team launches a public bug bounty. What is the most likely outcome?
  68. 68. Which two backup properties most directly determine whether an organisation can recover from ransomware without paying? Choose two.
  69. 69. An executive proposes paying a ransom because it will be faster than restoring. Which point should the security lead make?
  70. 70. An organisation restores cleanly from backup after a ransomware attack, yet still faces a serious problem. What is it?
  71. 71. Which parties should an incident response plan identify before an incident occurs?
  72. 72. Why must the exact time an incident was detected be recorded precisely?
  73. 73. A company hires a payroll bureau that processes employee data strictly on the company's written instructions. Under privacy regulation, what are their roles?
  74. 74. A team chooses a cloud region purely on latency. Which consideration have they overlooked?
  75. 75. Which measure reduces breach impact before any technical control is applied?
  76. 76. Why is an over-long records retention period a security problem as well as a storage cost?
  77. 77. A service will only let users register if they also consent to their data being used for unrelated marketing analysis. What is wrong with this?
  78. 78. An identity proofing system wrongly rejects a legitimate applicant. What must the provider offer?
  79. 79. Which artefact does an authorising official read to understand a system's control effectiveness before making the authorisation decision?
  80. 80. A weakness is found that will not be remediated for nine months. Where should it be recorded so it stays visible and owned?
  81. 81. A team applies a NIST control baseline exactly as published with no changes. What have they misunderstood?
  82. 82. Several similar healthcare systems each need the same tailored control set. Which construct avoids each of them tailoring the baseline separately?
  83. 83. A supplier passed its assessment two years ago and has not been reviewed since. What risk does this create?
  84. 84. An organisation's SaaS provider depends on a third-party payment processor that the organisation has never assessed. What is this exposure called?
  85. 85. A batch of network cards turns out to be counterfeit, though no malicious code is present. Why is this still a supply chain security issue?
  86. 86. A critical flaw is announced in a widely used logging library. Which artefact turns finding affected products from a research project into a lookup?
  87. 87. Which two elements must a change management process require before an authorised change is applied? Choose two.
  88. 88. An engineer applies an emergency fix at 3am without raising a ticket, arguing the outage justified it. What is the correct position?
  89. 89. What does keeping infrastructure configuration under version control give a change management process?
  90. 90. An organisation adopts a security framework and needs to know what work to budget for. Which activity produces that list?
  91. 91. A client asks for a test that begins with no inside information about the environment. Which engagement type is this?
  92. 92. During a test, an assessor gathers information about the target using only public records and search engines. What is the main advantage of this approach?
  93. 93. Mid-engagement, a tester discovers they can reach a system that was not listed in the agreed scope. What should they do?
  94. 94. A penetration test report is filed after review and no findings are tracked. What is the consequence?
  95. 95. A team wants to test decision-making and plan clarity for a ransomware scenario at the lowest cost. Which exercise type fits?
  96. 96. After a successful tabletop exercise, a manager states the recovery capability is now proven. Why is that overstating the result?
  97. 97. A continuity plan written three years ago has never been exercised. What is the most likely problem with it now?
  98. 98. Why do redundant power and environmental monitoring belong in a contingency plan rather than only in daily operations?
  99. 99. Why do perimeter controls contribute little against an insider threat?
  100. 100. A department signs up for an unapproved file-sharing service. What is the primary security concern?
  101. 101. Why is asset management treated as a security control rather than an IT housekeeping task?
  102. 102. At which stage of the asset lifecycle does data most often escape the organisation's control?
  103. 103. A board asks why it cannot act on the security team's quarterly report. The report lists control gaps by identifier. What is the underlying problem?
  104. 104. Which statement correctly describes the relationship between cybersecurity risk and privacy risk?
  105. 105. A system cannot meet a mandated control. Which response keeps this within governance rather than making it an audit finding?
  106. 111. An upgrade would fix a vulnerability, but the new version's cryptographic modules are not yet FIPS-validated and the organisation must use validated modules. What does this illustrate?
  107. 230. A team copies a production database into a test environment to reproduce a bug. What must happen first?
  108. 250. An organisation uses a third-party disposal vendor. What evidence should it retain?
  109. 252. Why does a control catalogue matter more than a list of security intentions?
  110. 410. A team selects a hot site before running the business impact analysis. What is the problem with that order?
  111. 454. An analyst joins a sector information sharing community. Which notation tells them how widely each item may be redistributed?
  112. 499. An organisation handles a major incident well but never holds a review afterwards. What has it lost?
  113. 500. Which dependency is most likely to delay an incident response if it was not settled in advance?
  114. 509. Litigation is anticipated and the retention schedule is about to delete relevant mailboxes. What must be issued?
  115. 544. What is the trade-off of escrowing an encryption key?
  116. 562. Which step was added to the Risk Management Framework in Revision 2, and what does it establish?
  117. 563. What does the risk executive function provide that individual system authorisations cannot?
  118. 564. Why are Cybersecurity Framework outcomes written to be sector-, country- and technology-neutral?
  119. 565. How does NIST expect supply chain cybersecurity to be handled?
  120. 566. Why can a medium-severity vulnerability legitimately outrank a high-severity one in a remediation queue?
  121. 567. An analyst wants to post a TLP:GREEN advisory on the company's public blog. Is that permitted?
  122. 568. A team translates an advisory into Spanish, including translating the TLP label. What is wrong?
  123. 569. Which artefact gives a security researcher a documented route to report a finding?
  124. 570. How does coordinated disclosure differ from full disclosure?
  125. 571. An organisation confirms backups complete successfully every night. What does CISA say this does not establish?
  126. 572. What makes ongoing authorisation less costly than a periodic full reassessment?
  127. 573. What changed about the structure of the NIST control catalogue in Revision 5?
  128. 574. A supplier ships a product with serious flaws caused by weak development practices, with no adversary involved. Which control addresses this?
  129. 575. A risk assessment is commissioned to inform a decision about a single application's deployment. At which tier should it be run?
  130. 610. How does continuity of operations planning differ from information system contingency planning?