Tyler Hampton
Test por , creado hace más de 1 año

Explain the importance of risk-related concepts.

12
0
0
Tyler Hampton
Creado por Tyler Hampton hace alrededor de 6 años
Cerrar

S+ Objective 2.1 Quiz

Pregunta 1 de 15

1

A security manager needs to identify a policy that will reduce the risk of personnel within an organization colluding to embezzle company funds. Which of the following is the BEST choice?

Selecciona una de las siguientes respuestas posibles:

  • AUP

  • Training

  • Mandatory Vacations

  • Time-of-Day Restrictions

Explicación

Pregunta 2 de 15

1

Your organization includes a software development division within the IT department. One developer writes and maintains applications for the Sales and Marketing departments. A second developer writes and maintains applications for the Payroll department. Once a year, they have to switch roles for at least a month. What is the purpose of this practice?

Selecciona una de las siguientes respuestas posibles:

  • To enforce a separation of duties policy

  • To enforce a mandatory vacation policy

  • To enforce a job rotation policy

  • To enforce an acceptable use policy

Explicación

Pregunta 3 de 15

1

Which of the following accurately identifies the primary security control classifications?

Selecciona una de las siguientes respuestas posibles:

  • Role-based, mandatory, and discretionary

  • Technical, management, and operational

  • Physical, logical, and technical

  • Technical and preventative

Explicación

Pregunta 4 de 15

1

Administrators have noticed an increased workload recently. Which of the following can cause an increased workload from incorrect reporting?

Selecciona una de las siguientes respuestas posibles:

  • False negatives

  • False positives

  • Separation of Duties

  • Signature-based IDSs

Explicación

Pregunta 5 de 15

1

Which of the following is most closely associated with residual risk?

Selecciona una de las siguientes respuestas posibles:

  • Risk acceptance

  • Risk Avoidance

  • Risk Deterrence

  • Risk Mitigation

Explicación

Pregunta 6 de 15

1

You need to calculate the ALE for a server. The value of the server is $3,000, but it has crashed 10 times in the past year. Each time it crashed, it resulted in a 10 percent loss. What is the ALE?

Selecciona una de las siguientes respuestas posibles:

  • $300

  • $500

  • $3,000

  • $30,000

Explicación

Pregunta 7 de 15

1

You need to calculate the expected loss on a single incident. Which of the following value combinations would you MOST likely use?

Selecciona una de las siguientes respuestas posibles:

  • ALE and ARO

  • ALE and SLE

  • SLE and ARO

  • ARO and ROI

Explicación

Pregunta 8 de 15

1

You are helping implement your company's business continuity plan. For one system, the plan requires an RTO of five hours and an RPO of one day. Which of the following would meet this requirement?

Selecciona una de las siguientes respuestas posibles:

  • Ensure the system can be restored within five hours and ensure it does not lose more than one day of data.

  • Ensure the system can be restored within one day and ensure it does not lose more than five hours of data.

  • Ensure the system can be restored between five hours and one day after an outage

  • Ensure critical systems can be restored within five hours and noncritical systems can be restored within one day.

Explicación

Pregunta 9 de 15

1

Your organization is evaluating replacement HVAC systems and is considering increasing current capacities. Which of the following is a potential security benefit of increasing the HVAC capabilities?

Selecciona una de las siguientes respuestas posibles:

  • Lower MTBF times of hardware components due to lower temperatures.

  • Higher MTBF times of hardware components due to lower temperatures.

  • Lower MTTR times of hardware components due to lower temperatures.

  • Higher MTTR times of hardware components due to lower temperatures.

Explicación

Pregunta 10 de 15

1

An attacker was able to sneak into your building but was unable to open the server room door. He bashed the proximity badge reader with a portable fire extinguisher and the door opened. What is the MOST likely reason that the door opened?

Selecciona una de las siguientes respuestas posibles:

  • The access system was designed to fail-open.

  • The access system was designed to fail-close.

  • The access system was improperly installed.

  • The portable fire extinguisher included a proximity badge.

Explicación

Pregunta 11 de 15

1

Which of the following is an environmental control?

Selecciona una de las siguientes respuestas posibles:

  • EMI shielding

  • Fencing

  • Video Surveillance

  • Motion Detection

Explicación

Pregunta 12 de 15

1

An organization has purchased fire insurance to manage the risk of a potential fire. What method are they using?

Selecciona una de las siguientes respuestas posibles:

  • Risk acceptance

  • Risk avoidance

  • Risk transference

  • Risk mitigation

Explicación

Pregunta 13 de 15

1

You are asked to identify the number of times a specific type of incident occurs per year. Which of the following BEST identifies this?

Selecciona una de las siguientes respuestas posibles:

  • ALE

  • ARO

  • MTTF

  • SLE

Explicación

Pregunta 14 de 15

1

Lisa needs to calculate the total ALE for a group of servers used in the network. During the past two years, five of the servers failed. The hardware cost to replace each server is $3,500, and the downtime has resulted in $2,500 of additional losses. What is the ALE?

Selecciona una de las siguientes respuestas posibles:

  • $6,000

  • $18,000

  • $15,000

  • $30,000

Explicación

Pregunta 15 de 15

1

Which of the following is a management control?

Selecciona una de las siguientes respuestas posibles:

  • Encryption

  • Security Policy

  • Least Privilege

  • Change Management

Explicación