True or false: The qualitative model is intended to provide a precise numerical prediction of harm.
8 Security in Practice Online Quiz Questions
Use this free practice quiz with 20 questions to review 8 Security in Practice, test your knowledge, and prepare for your next test or exam.
A business cannot eliminate a particular financial risk, but it can arrange insurance to share some potential losses. Which risk response does this illustrate?
- A
Ignore the risk because it has not caused harm yet.
- B
Use insurance or a contract to share some of the consequences.
- C
Accept the risk without review or approval.
- D
Apply safeguards that remove every possible consequence.
What term describes the risk that remains after safeguards have been applied?
A risk arises when a could exploit a and cause harm.
True or false: Accepting a risk should be an informed decision by someone with appropriate authority, rather than an assumption that an unexamined risk is harmless.
- A
True
- B
False
According to the material, each account should receive only the access needed for what?
To check whether backups can support recovery, a reviewer should seek evidence such as a , not rely only on a written policy.
A team has completed a system review. When should it revisit that review?
- A
Only when the system is first built.
- B
Only after a security incident causes confirmed harm.
- C
After significant system changes or incidents, and periodically.
- D
Only when the review's original owner leaves.
Select all functions in the NIST Cybersecurity Framework 2.0.
- A
Govern
- B
Identify
- C
Protect
- D
Detect
- E
Respond
- F
Recover
- G
Encrypt
- H
Insure
During a practical system review, which actions directly check safeguards or evidence that protections work? Select all that apply.
- A
Review access settings and authentication.
- B
Check whether software updates are applied.
- C
Test whether backups can be restored.
- D
Review logging and incident procedures.
- E
Set the review's scope and purpose.
- F
List the system's devices and applications.
An online store discovers that an administrator account uses password-only login. Which single action directly addresses the risk that a stolen password could let an attacker access that account?
- A
Train staff to recognize phishing messages.
- B
Keep an offline copy of important records.
- C
Require multifactor authentication for administrator accounts.
- D
Separate systems according to their roles.
An online store is comparing two risks: account takeover, given valuable customer accounts, reused passwords, and an internet-accessible login page; and a temporary outage of a nonessential internal report. Which conclusion best applies risk-based prioritization?
- A
Prioritize account takeover because valuable accounts, reused passwords, and an internet-accessible login create a serious plausible risk.
- B
Prioritize the internal report outage automatically, regardless of its impact or likelihood.
- C
Treat both situations as equal because they involve different kinds of systems.
- D
Ignore account takeover unless an attacker has already succeeded.
A company finds that an internet-facing service handling sensitive customer records is running outdated software. Describe how a practical security review should assess and manage this risk, including the potential harm, the threat and weakness, prioritization, a response, verification, and follow-up.
A team reviewing an online service inventories its applications, cloud services, vendor connections, backups, and sensitive-data locations. Which system-review step is the team performing?
- A
Set scope and purpose
- B
Map assets and dependencies
- C
Trace likely threat paths
- D
Prioritize and assign action
Before reviewing a payment platform, a team identifies the system owner, its users, its important services, and the decisions the review should inform. Which review step does this describe?
- A
Map assets and dependencies
- B
Check safeguards and evidence
- C
Set scope and purpose
- D
Reassess after change
A small business wants its security to remain effective even if one safeguard fails. Which plan best applies defense in depth?
- A
Use varied safeguards so one control's failure does not determine the outcome
- B
Use the same safeguard repeatedly so every failure is handled identically
- C
Choose one strong safeguard and remove the others
- D
Apply safeguards only after an incident has caused harm
A review finds that a business's administrative application has missed security updates and uses an unnecessarily exposed configuration. Which defense-in-depth layer most directly addresses these issues?
- A
People and policy
- B
Identity and access
- C
Detection and recovery
- D
Devices and applications
True or false: Using several safeguards guarantees that a system cannot be harmed, so the organization no longer needs to consider whether risks remain.
- A
True
- B
False
During a system review, a team traces how a phishing message could lead to account compromise and harm. What two-word term names this route from a possible event toward harm?
A company decides not to launch a feature because it does not want to undertake the risky activity at all. Which single-word risk response describes this decision?