6. Security and Ethics
Risk Management — Quiz
Test your understanding of risk management with 5 practice questions.
Practice Questions
Question 1
Which of the following risk management frameworks is specifically designed for federal information systems in the United States and provides a comprehensive, lifecycle-based approach to security authorization?
Question 2
In the context of information system risk management, what is the primary objective of a 'control'?
Question 3
An organization is implementing a new customer relationship management (CRM) system. During the risk assessment, they identify a potential risk of unauthorized access to sensitive customer data. Which of the following would be the most effective technical control to mitigate this specific risk?
Question 4
Which of the following best describes the concept of 'inherent risk' in information system risk management?
Question 5
A company is performing a quantitative risk assessment for a potential data breach. They estimate the Single Loss Expectancy (SLE) to be $$ \$100,000 $ and the Annualized Rate of Occurrence (ARO) to be $ 0.05 $$. What is the Annualized Loss Expectancy (ALE)?
