Information Security Management Examination (SG) | Section A Risk and Access Management 05
Problem 1
Which term refers to stopping the activity or the use of the asset that causes the risk in the first place?
View explanation
The answer is risk avoidance, the response of stopping the activity or the use of the asset that causes the risk in the first place.
Problem 2
Which term refers to introducing controls to make the likelihood or the impact smaller?
View explanation
The answer is risk mitigation, the response of introducing controls to make the likelihood or the impact smaller.
Problem 3
Which term refers to passing part of the loss to a third party through insurance or a contract?
View explanation
The answer is risk transfer, the response of passing part of the loss to a third party through insurance or a contract.
Problem 4
Which term refers to accepting a recognised risk in view of the cost of countermeasures and the like?
View explanation
The answer is risk retention, the response of accepting a recognised risk in view of the cost of countermeasures and the like.
Problem 5
Which term refers to the person who manages a particular risk and has the accountability and authority for responding to it?
View explanation
The answer is risk owner, the person who manages a particular risk and has the accountability and authority for responding to it.
Problem 6
Which term refers to the risk that remains after controls have been implemented?
View explanation
The answer is residual risk, the risk that remains after controls have been implemented.
Problem 7
Which term refers to an event or presence that could cause harm to information assets?
View explanation
The answer is threat, an event or presence that could cause harm to information assets.
Problem 8
Which term refers to a weakness in an asset or a control that a threat could exploit?
View explanation
The answer is vulnerability, a weakness in an asset or a control that a threat could exploit.
Problem 9
Which term refers to a record listing where information assets are, who manages them and how important they are?
View explanation
The answer is asset inventory, a record listing where information assets are, who manages them and how important they are.
Problem 10
Which term refers to sorting information by importance such as its confidentiality and setting rules for handling it?
View explanation
The answer is information classification, sorting information by importance such as its confidentiality and setting rules for handling it.
Problem 11
Which term refers to granting only the minimum access rights needed for the job?
View explanation
The answer is principle of least privilege, granting only the minimum access rights needed for the job.
Problem 12
Which term refers to the control of assigning tasks such as requesting and approving to different people to curb fraud and error?
View explanation
The answer is separation of duties, the control of assigning tasks such as requesting and approving to different people to curb fraud and error.
Problem 13
Which term refers to strictly controlling who uses IDs with administrator rights, for what purpose, for how long and with what operations recorded?
View explanation
The answer is privileged ID management, strictly controlling who uses IDs with administrator rights, for what purpose, for how long and with what operations recorded.
Problem 14
Which term refers to periodically confirming that users and their rights are still appropriate and removing those no longer needed?
View explanation
The answer is account review, periodically confirming that users and their rights are still appropriate and removing those no longer needed.
Problem 15
Which term refers to an attack that tries a small number of common passwords against many IDs?
View explanation
The answer is password spraying, an attack that tries a small number of common passwords against many IDs.
Problem 16
Which term refers to an attack that reuses ID and password pairs leaked from another service to attempt logins?
View explanation
The answer is credential stuffing, an attack that reuses ID and password pairs leaked from another service to attempt logins.
Problem 17
Which term refers to an attack that gets between two communicating parties to eavesdrop or tamper?
View explanation
The answer is man-in-the-middle attack, an attack that gets between two communicating parties to eavesdrop or tamper.
Problem 18
Which term refers to an attack that plants false information in a DNS cache to send users to a malicious site?
View explanation
The answer is DNS cache poisoning, an attack that plants false information in a DNS cache to send users to a malicious site.
Problem 19
Which term refers to an attack that steals a valid session identifier to impersonate a legitimate user?
View explanation
The answer is session hijacking, an attack that steals a valid session identifier to impersonate a legitimate user.
Problem 20
Which term refers to an attack that makes a logged-in user send an unintended request to a website?
View explanation
The answer is CSRF, an attack that makes a logged-in user send an unintended request to a website.
Result
More sets in this exam
- Information Security Management Examination (SG) | Section A Security Fundamentals 01
- Information Security Management Examination (SG) | Section A Threats and Attack Techniques 02
- Information Security Management Examination (SG) | Section A Cryptography, Authentication and Controls 03
- Information Security Management Examination (SG) | Section A Security Management and Law 04
- Information Security Management Examination (SG) | Section A Security Properties and Design Principles Questions 07
- Information Security Management Examination (SG) | Section A Risk Treatment, Supplier, and Incident Management Questions 08