Study sets
English

Information Security Management Examination (SG) | Section A Risk and Access Management 05

1 / 200.0s

Problem 1

Which term refers to stopping the activity or the use of the asset that causes the risk in the first place?

View explanation

The answer is risk avoidance, the response of stopping the activity or the use of the asset that causes the risk in the first place.

Problem 2

Which term refers to introducing controls to make the likelihood or the impact smaller?

View explanation

The answer is risk mitigation, the response of introducing controls to make the likelihood or the impact smaller.

Problem 3

Which term refers to passing part of the loss to a third party through insurance or a contract?

View explanation

The answer is risk transfer, the response of passing part of the loss to a third party through insurance or a contract.

Problem 4

Which term refers to accepting a recognised risk in view of the cost of countermeasures and the like?

View explanation

The answer is risk retention, the response of accepting a recognised risk in view of the cost of countermeasures and the like.

Problem 5

Which term refers to the person who manages a particular risk and has the accountability and authority for responding to it?

View explanation

The answer is risk owner, the person who manages a particular risk and has the accountability and authority for responding to it.

Problem 6

Which term refers to the risk that remains after controls have been implemented?

View explanation

The answer is residual risk, the risk that remains after controls have been implemented.

Problem 7

Which term refers to an event or presence that could cause harm to information assets?

View explanation

The answer is threat, an event or presence that could cause harm to information assets.

Problem 8

Which term refers to a weakness in an asset or a control that a threat could exploit?

View explanation

The answer is vulnerability, a weakness in an asset or a control that a threat could exploit.

Problem 9

Which term refers to a record listing where information assets are, who manages them and how important they are?

View explanation

The answer is asset inventory, a record listing where information assets are, who manages them and how important they are.

Problem 10

Which term refers to sorting information by importance such as its confidentiality and setting rules for handling it?

View explanation

The answer is information classification, sorting information by importance such as its confidentiality and setting rules for handling it.

Problem 11

Which term refers to granting only the minimum access rights needed for the job?

View explanation

The answer is principle of least privilege, granting only the minimum access rights needed for the job.

Problem 12

Which term refers to the control of assigning tasks such as requesting and approving to different people to curb fraud and error?

View explanation

The answer is separation of duties, the control of assigning tasks such as requesting and approving to different people to curb fraud and error.

Problem 13

Which term refers to strictly controlling who uses IDs with administrator rights, for what purpose, for how long and with what operations recorded?

View explanation

The answer is privileged ID management, strictly controlling who uses IDs with administrator rights, for what purpose, for how long and with what operations recorded.

Problem 14

Which term refers to periodically confirming that users and their rights are still appropriate and removing those no longer needed?

View explanation

The answer is account review, periodically confirming that users and their rights are still appropriate and removing those no longer needed.

Problem 15

Which term refers to an attack that tries a small number of common passwords against many IDs?

View explanation

The answer is password spraying, an attack that tries a small number of common passwords against many IDs.

Problem 16

Which term refers to an attack that reuses ID and password pairs leaked from another service to attempt logins?

View explanation

The answer is credential stuffing, an attack that reuses ID and password pairs leaked from another service to attempt logins.

Problem 17

Which term refers to an attack that gets between two communicating parties to eavesdrop or tamper?

View explanation

The answer is man-in-the-middle attack, an attack that gets between two communicating parties to eavesdrop or tamper.

Problem 18

Which term refers to an attack that plants false information in a DNS cache to send users to a malicious site?

View explanation

The answer is DNS cache poisoning, an attack that plants false information in a DNS cache to send users to a malicious site.

Problem 19

Which term refers to an attack that steals a valid session identifier to impersonate a legitimate user?

View explanation

The answer is session hijacking, an attack that steals a valid session identifier to impersonate a legitimate user.

Problem 20

Which term refers to an attack that makes a logged-in user send an unintended request to a website?

View explanation

The answer is CSRF, an attack that makes a logged-in user send an unintended request to a website.