• Home
  • Textbooks
  • The SSCP Prep Guide: Mastering the Seven Key Areas of System Security
  • Domain 4: Risk, Response, and Recovery

The SSCP Prep Guide: Mastering the Seven Key Areas of System Security

Debra S. Isaac, Michael J. Isaac

Chapter 5

Domain 4: Risk, Response, and Recovery - all with Video Answers

Educators


Chapter Questions

Problem 1

Which choice gives the BEST description of risk reduction?
a. Altering elements of the enterprise in response to a risk analysis
b. Removing all risk to the enterprise at any cost
c. Assigning any costs associated with risk to a third party
d. Assuming all costs associated with the risk internally

Check back soon!
02:02

Problem 2

Which choice is an example of a incident due to a human event, rather than a non-human incident?
a. Sabotage
b. Financial collapse
c. Structure collapse
d. Utility failure

Lizabeth Meany
Lizabeth Meany
Numerade Educator

Problem 3

Place the following backup processing alternatives in order from the least-expensive solution to the most expensive:
a. Warm site
b. Hot site
c. Cold site
d. Mutual aid agreement

Check back soon!

Problem 4

Which group represents the MOST likely source of an asset loss through inappropriate computer use?
a. Crackers
b. Employees
c. Hackers
d. Flood

Check back soon!

Problem 5

Which statement about risk is not accurate?
a. Risk is identified and measured by performing a risk analysis.
b. Risk is controlled through the application of safeguards and countermeasures.
c. Risk is managed by periodically reviewing and taking responsible actions based on the risk.
d. Risk can be completely eliminated through risk management.

Check back soon!

Problem 6

Which statement most accurately describes contingency operations and recovery?
a. The function of identifying, evaluating (measuring), and controlling risk
b. Activities that are performed when a security-related incident occurs
c. Planned activities that enable the critical business functions to return to normal operations
d. Transferring risk to a third-party insurance carrier

Check back soon!

Problem 7

Which choice is NOT a commonly accepted definition for a disaster?
a. An occurrence that is outside the normal computing function
b. An occurrence or imminent threat to the entity of widespread or severe damage, injury, loss of life, or loss of property
c. An emergency that is beyond the normal response resources of the entity
d. A suddenly occurring event that has a long-term negative impact on social life

Check back soon!

Problem 8

Which choice MOST accurately describes a threat?
a. Any weakness in an information system
b. Protective controls
c. Multi-layered controls
d. Potential for a source to exploit a specific vulnerability

Check back soon!

Problem 9

What is considered the major disadvantage to employing a "hot" site for disaster recovery?
a. Exclusivity is assured for processing at the site.
b. Annual testing is required to maintain the site.
c. The site is immediately available for recovery.
d. Maintaining the site is expensive.

Check back soon!

Problem 10

Which choice MOST accurately describes a safeguard?
a. Potential for a source to exploit a specific vulnerability
b. Controls I -place that provide some amount of protection for the asset
c. Weakness in internal controls that could be exploited by a threat or threat agent
d. A control designed to counteract an asset

Check back soon!
01:51

Problem 11

Which choice is NOT an accurate statement about an organization's incident-handling response capability?
a. It should be used to provide the ability to respond quickly and effectively to an incident.
b. It should be used to prevent future damage from incidents.
c. It should be used to detect and punish senior-level executive wrong-doing.
d. It should be used to contain and repair damage done from incidents.

Oluwadamilola Ameobi
Oluwadamilola Ameobi
Numerade Educator

Problem 12

Which choice is NOT a role or responsibility of the person designated to manage the contingency planning process?
a. Providing direction to senior management
b. Providing stress-reduction programs to employees after an event
c. Ensuring the identification of all critical business functions
d. Integrating the planning process across business units

Check back soon!

Problem 13

Which choice MOST accurately describes a countermeasure?
a. An event with the potential to harm an information system through unauthorized access
b. Controls implemented as a direct result of a security analysis
c. The Annualized Rate of Occurrence (ARO) multiplied by the Single Loss Exposure (SRO); ARO $\times$ SLE
d. A company resource that could be lost due to an incident

Check back soon!

Problem 14

Which disaster recovery/emergency management plan testing type is considered the most cost-effective and efficient way to identify areas of overlap in the plan before conducting more demanding training exercises?
a. Full-scale exercise
b. Walk-through drill
c. Table-top exercise test
d. Evacuation drill

Check back soon!
View

Problem 15

Which choice MOST closely depicts the difference between qualitative and quantitative risk analysis?
a. A quantitative RA does not use the hard costs of losses, and a qualitative RA does.
b. A quantitative RA makes a cost-benefit analysis simpler.
c. A quantitative RA results in a subjective (High, Medium, or Low) result.
d. A quantitative RA cannot be automated.

Ronald Prasad
Ronald Prasad
Numerade Educator

Problem 16

Which choice is an incorrect description of a control?
a. Detective controls discover attacks and trigger preventative or corrective controls.
b. Controls are the countermeasures for vulnerabilities.
c. Corrective controls reduce the effect of an attack.
d. Corrective controls reduce the likelihood of a deliberate attack.

Check back soon!
02:06

Problem 17

What is the main advantage of using a qualitative impact analysis over a quantitative analysis?
a. Identifies areas for immediate improvement.
b. Provides a rationale for finding effective security controls.
c. Makes a cost-benefit analysis simpler.
d. Provides specific measurements of the impacts' magnitude.

Ahmed Ali
Ahmed Ali
Numerade Educator

Problem 18

Which choice is NOT a common information-gathering technique when performing a risk analysis?
a. Distributing a questionnaire
b. Employing automated risk assessment tools
c. Interviewing terminated employees
d. Reviewing existing policy documents

Check back soon!
View

Problem 19

Put the following general steps in a qualitative risk analysis in order:
a. The team prepares its findings and presents them to management.
b. A scenario is written to address each identified threat.
c. Business unit managers review the scenario for a reality check.
d. The team works through each scenario by using a threat, asset, and safeguard.

Bryan Kim
Bryan Kim
Numerade Educator
02:09

Problem 20

Which choice is usually the number one-used criterion to determine the classification of an information object?
a. Useful life
b. Value
c. Age
d. Personal association

Alexander Cheng
Alexander Cheng
Numerade Educator
02:10

Problem 21

What is the prime objective of risk management?
a. Reduce the risk to a tolerable level.
b. Reduce all risk regardless of cost.
c. Transfer any risk to external third parties.
d. Prosecute any employees that are violating published security policies.

Patina Herring
Patina Herring
Numerade Educator

Problem 22

Which choice best describes a business asset?
a. Events or situations that could cause a financial or operational impact to the organization
b. Protection devices or procedures in place that reduce the effects of threats
c. Competitive advantage, credibility, or goodwill
d. Personnel compensation and retirement programs

Check back soon!

Problem 23

Which choice is the MOST accurate description of a "cold" site?
a. A backup processing facility with adequate electrical wiring and air conditioning but no hardware or software installed
b. A backup processing facility with most hardware and software installed, which can be operational within a matter of days
c. A backup processing facility with all hardware and software installed and 100 percent compatible with the original site: operational within hours
d. A mobile trailer with portable generators and air conditioning

Check back soon!

Problem 24

Which question is NOT accurate regarding the process of risk assessment?
a. The likelihood of a threat must be determined as an element of the risk assessment.
b. The level of impact of a threat must be determined as an element of the risk assessment.
c. Risk assessment is the final result of the risk management methodology.
d. Risk assessment is the first process in the risk management methodology.

Check back soon!
04:30

Problem 25

Which statement is NOT correct about safeguard selection in the risk analysis process?
a. Maintenance costs need to be included in determining the total cost of the safeguard.
b. The most commonly considered criteria is the cost effectiveness of the safeguard.
c. The best possible safeguard should always be implemented regardless of cost.
d. Many elements need to be considered in determining the total cost of the safeguard.

Samriddhi Singh
Samriddhi Singh
Numerade Educator

Problem 26

Which choice most accurately reflects the goals of risk mitigation?
a. Analyzing the effects of a business disruption and preparing the company's response
b. Analyzing and removing all vulnerabilities and threats to security within the organization
c. Defining the acceptable level of risk that the organization can tolerate and assigning any costs associated with loss or disruption to a third party, such as an insurance carrier.
d. Defining the acceptable level of risk that the organization can tolerate and reducing risk to that level.

Check back soon!
05:42

Problem 27

Which choice represents an application or system demonstrating a need for a high level of availability protection and control?
a. The application contains proprietary business information and other financial information, which if disclosed to unauthorized sources, could cause unfair advantage for vendors, contractors, or individuals and could result in financial loss or adverse legal action to user organizations.
b. Unavailability of the system could result in inability to meet payroll obligations and could cause work stoppage and failure of user organizations to meet critical mission requirements. The system requires 24-hour access.
c. The mission of this system is to produce local weather forecast information that is made available to the news media forecasters and the general public at all times. None of the information requires protection against disclosure.
d. Destruction of the information would require significant expenditures of time and effort to replace. Although corrupted information would present an inconvenience to the staff, most information, and all vital information, is backed up by either paper documentation or on disk.

Jennifer Stoner
Jennifer Stoner
Numerade Educator
00:35

Problem 28

Put the five disaster recovery testing types in their proper order, from the most extensive to the least.
a. Full-interruption
b. Checklist
c. Structured walk-through
d. Parallel
e. Simulation

Maxime Rossetti
Maxime Rossetti
Numerade Educator

Problem 29

Which type of backup subscription service listed would require the longest recovery time?
a. A hot site
b. A mobile or rolling backup service
c. A warm site
d. A cold site

Check back soon!

Problem 30

Which of the following would best describe a "hot" backup site?
a. A computer facility with electrical power and HVAC but with no applications or recent data installed on the workstations or servers prior to the event
b. A computer facility available with electrical power and HVAC and some file/print servers, although the applications are not installed or configured and all of the needed workstations might not be on site or ready to begin processing
c. A computer facility with no electrical power or HVAC
d. A computer facility with electrical power and HVAC, all needed applications installed and configured on the file/print servers and enough workstations present to begin processing

Check back soon!