Module 5 - Risk Assessment Flashcards

1
Q

Threat

A

A threat is the potential that a vulnerability will be identified and exploited

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Threat Vector

A

A threat vector is the path that an attacker utilises to impact the target.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Threat source types

A
  • Adversarial: Threats from individuals, groups, organizations or nations.
  • Accidental: Actions that occur without a malicious intent.
  • Structural: Equipment and software failures.
  • Environmental: External disasters that can be either natural or human-caused, such as fires and floods.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 4 goals of a risk analysis?

A
  1. Identify assets and their value.
  2. Identify vulnerabilities and threats.
  3. Quantify the probability and impact of the identified threats.
  4. Balance the impact of the threat against the cost of the countermeasure.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Quantitative Risk Analysis

A

A quantitative risk analysis assigns numbers to the risk analysis process. In this example, the asset value is the replacement cost of the file server (the asset). The value of an asset can also be measured by the income gained through the use of the asset.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

EF

A

The exposure factor (EF) is a subjective value expressed as a percentage of the file server lost due to a particular threat. If total loss occurs, the EF equals 1.0 (100%).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

ARO

A

The annualized rate of occurrence (ARO) is the probability that a loss will occur during the year. An ARO can be greater than 100% if a loss can occur more than once a year.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

ALE

A

The calculation of the annual loss expectancy (ALE) gives management some guidance on what an organization should spend to protect the file server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Qualitative Risk Analysis

A

Qualitative risk analysis uses opinions and scenarios plotting the likelihood of a threat against its impact. For example, a server failure may be likely, but its impact may only be marginal.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Risk Mitigation

A

Mitigation involves reducing the likelihood or severity of a loss from threats. Many technical controls mitigate risk, including authentication systems, file permissions and firewalls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly