Deck 3: Assessing Risk and Impact

Full screen (f)
exit full mode
Question
What is the primary goal of a risk assessment?

A)Recovering from a disaster
B)Mitigating loss of productivity
C)Developing a disaster recovery plan
D)Developing a business continuity plan
Use Space or
up arrow
down arrow
to flip the card.
Question
In today's world,the possibility of attack by outside agencies has ___________ dramatically.

A)been exaggerated
B)been downplayed
C)decreased
D)increased
Question
Each business process contributes to the operation of the enterprise,but there are some without which the enterprise cannot carry out the others.What are these called?

A)Disaster recovery processes
B)Mission-critical processes
C)Risk management processes
D)Risk assessment processes
Question
It is important to __________ for preventive measures and the recovery from any disaster situation.

A)set priorities
B)allow
C)compete
D)look
Question
The assessment of various levels of risks cannot be compared to each other unless the methods used to assess them are _________.

A)the same
B)diverse
C)simplified
D)detailed
Question
A(n)__________ is the chance that someone or something could be harmed by a hazard..

A)recovery plan
B)assessment
C)risk
D)disaster
Question
Why must a disaster plan be continually revisited and updated?

A)Threats change
B)Assets change
C)Processes and abilities within the organization change
D)All of the above
Question
How is asset-based risk assessment different from disaster-based risk assessment?

A)You assess all assets,rather than hazards.
B)You assess all hazards,rather than assets.
C)You assess all risks,rather than assets.
D)You assess all assets,rather than risks.
Question
One of the first considerations in the business impact analysis is the __________.

A)assets that are vulnerable
B)service-level agreements that the organization must meet
C)risks
D)hazards
Question
Which assets must be considered when using asset-based risk assessment?

A)all intangible assets
B)all tangible assets
C)all assets
D)those assets valued at more than a determined threshold
Question
Why must backups be tested?

A)Without knowing that they can be recovered,backups are useless
B)To determine the cost if they are needed during a disaster recovery
C)To determine if they are needed
D)All of the above
Question
In the disaster recovery plan,each response should detail the use of resources and assign only those resources needed to _________ the problem.

A)assess
B)quantify
C)delegate
D)fix
Question
Each __________ needs a plan and a measured response spelled out in the disaster recovery plan.

A)assessment
B)recovery
C)threat
D)plan
Question
The best disaster is the one you don't have to __________.

A)plan for
B)avoid
C)recover from
D)assess
Question
The possibility of harm or loss from any given disaster is different depending on the __________.

A)organization
B)situation
C)severity of the disaster
D)All of the above
Question
Realistic ramifications and weights should be assigned to all events and potential ______________.
Question
A(n)__________ is anything that can cause harm.
Question
Which of the following is among the most difficult to recover?

A)Microfilm
B)Paper
C)Computer disks
D)Hard drives
Question
OCTAVE,a highly flexible assessment strategy,can be tailored to nearly any organization and can be very effective in identifying __________.

A)costs associated with disaster recovery
B)areas where the organization is most likely to be affected by a disaster recovery
C)areas where the organization is most likely to be affected by a disaster situation
D)areas where the organization is most likely to be affected by backup procedures
Question
__________ is a risk-based strategic assessment and planning technique used primarily for security but which also can be used for disaster recovery planning purposes.

A)OCTAVE
B)Business Impact Analysis
C)Asset-based Risk Assessment
D)Disaster-based Risk Assessment
Question
Functions need to be assessed by problems that their __________ will cause to the everyday operations of the business.
Question
In __________ process,rather than identifying the assets and disasters and then driving the process from those perspectives,you address the whole organization from the perspective of the perceived threats.
Question
For each asset that the company identifies,it needs to identify all the __________ that could impact each of the assets.
Question
All disasters and emergencies have a(n)________________ impact.
Question
A(n)__________ method of risk assessment needs to be applied across the business enterprise.
Question
Match between columns
Risk
magnitude of the potential loss
Risk
result of judging the worth or value of something or someone
Risk
the possibility of suffering harm or loss because of an event
Question
Match the following terms with their definitions:

-Business impact

A)magnitude of the potential loss
B)result of judging the worth or value of something or someone
C)the possibility of suffering harm or loss because of an event
Question
Match the following terms with their definitions:

-Assessment

A)magnitude of the potential loss
B)result of judging the worth or value of something or someone
C)the possibility of suffering harm or loss because of an event
Question
Match the following terms with there definitions:

-Disaster-based risk assessment

A)key to the ability to recover from disasters
B)based on awareness of existing risk factors
C)all possible hazards, rated
D)shows where the organization is in its disaster recovery process
Question
Match the following terms with there definitions:

-Tracking document

A)key to the ability to recover from disasters
B)based on awareness of existing risk factors
C)all possible hazards, rated
D)shows where the organization is in its disaster recovery process
Question
Match the following terms with there definitions:

-Accurately identified hazards

A)key to the ability to recover from disasters
B)based on awareness of existing risk factors
C)all possible hazards, rated
D)shows where the organization is in its disaster recovery process
Question
Match the following terms with there definitions:

-Weighted hazard list

A)key to the ability to recover from disasters
B)based on awareness of existing risk factors
C)all possible hazards, rated
D)shows where the organization is in its disaster recovery process
Question
Match each of the disaster-based risk assessment steps with its order of completion:

-First

A)assess hazards
B)implement controls
C)test and evaluate
D)identify hazards
E)develop controls and make risk decisions
Question
Match each of the disaster-based risk assessment steps with its order of completion:

-Second

A)assess hazards
B)implement controls
C)test and evaluate
D)identify hazards
E)develop controls and make risk decisions
Question
Match each of the disaster-based risk assessment steps with its order of completion:

-Third

A)assess hazards
B)implement controls
C)test and evaluate
D)identify hazards
E)develop controls and make risk decisions
Question
Match each of the disaster-based risk assessment steps with its order of completion:

-Fourth

A)assess hazards
B)implement controls
C)test and evaluate
D)identify hazards
E)develop controls and make risk decisions
Question
Match each of the disaster-based risk assessment steps with its order of completion:

-Fifth

A)assess hazards
B)implement controls
C)test and evaluate
D)identify hazards
E)develop controls and make risk decisions
Question
Match the following terms to their descriptions:

-Service Level Agreement

A)role that each area in the organization plays
B)addresses the organization from the perspective of perceived threats
C)the level of harm that may occur from any given threat or risk
D)a contract that spells out the terms of service that will be provided
Question
Match the following terms to their descriptions:

-Functional Area Input

A)role that each area in the organization plays
B)addresses the organization from the perspective of perceived threats
C)the level of harm that may occur from any given threat or risk
D)a contract that spells out the terms of service that will be provided
Question
Match the following terms to their descriptions:

-Business Impact Analysis

A)role that each area in the organization plays
B)addresses the organization from the perspective of perceived threats
C)the level of harm that may occur from any given threat or risk
D)a contract that spells out the terms of service that will be provided
Question
Match the following terms to their descriptions:

-Business Impact

A)role that each area in the organization plays
B)addresses the organization from the perspective of perceived threats
C)the level of harm that may occur from any given threat or risk
D)a contract that spells out the terms of service that will be provided
Question
Match the following OCTAVE phases with their respective phase number:

-Phase 1

A)Identify Infrastructure Vulnerabilities
B)Develop a Security Strategy
C)Create a Threat Profile
Question
Match the following OCTAVE phases with their respective phase number:

-Phase 2

A)Identify Infrastructure Vulnerabilities
B)Develop a Security Strategy
C)Create a Threat Profile
Question
Match the following OCTAVE phases with their respective phase number:

-Phase 3

A)Identify Infrastructure Vulnerabilities
B)Develop a Security Strategy
C)Create a Threat Profile
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/44
auto play flashcards
Play
simple tutorial
Full screen (f)
exit full mode
Deck 3: Assessing Risk and Impact
1
What is the primary goal of a risk assessment?

A)Recovering from a disaster
B)Mitigating loss of productivity
C)Developing a disaster recovery plan
D)Developing a business continuity plan
B
2
In today's world,the possibility of attack by outside agencies has ___________ dramatically.

A)been exaggerated
B)been downplayed
C)decreased
D)increased
D
3
Each business process contributes to the operation of the enterprise,but there are some without which the enterprise cannot carry out the others.What are these called?

A)Disaster recovery processes
B)Mission-critical processes
C)Risk management processes
D)Risk assessment processes
B
4
It is important to __________ for preventive measures and the recovery from any disaster situation.

A)set priorities
B)allow
C)compete
D)look
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
5
The assessment of various levels of risks cannot be compared to each other unless the methods used to assess them are _________.

A)the same
B)diverse
C)simplified
D)detailed
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
6
A(n)__________ is the chance that someone or something could be harmed by a hazard..

A)recovery plan
B)assessment
C)risk
D)disaster
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
7
Why must a disaster plan be continually revisited and updated?

A)Threats change
B)Assets change
C)Processes and abilities within the organization change
D)All of the above
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
8
How is asset-based risk assessment different from disaster-based risk assessment?

A)You assess all assets,rather than hazards.
B)You assess all hazards,rather than assets.
C)You assess all risks,rather than assets.
D)You assess all assets,rather than risks.
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
9
One of the first considerations in the business impact analysis is the __________.

A)assets that are vulnerable
B)service-level agreements that the organization must meet
C)risks
D)hazards
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
10
Which assets must be considered when using asset-based risk assessment?

A)all intangible assets
B)all tangible assets
C)all assets
D)those assets valued at more than a determined threshold
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
11
Why must backups be tested?

A)Without knowing that they can be recovered,backups are useless
B)To determine the cost if they are needed during a disaster recovery
C)To determine if they are needed
D)All of the above
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
12
In the disaster recovery plan,each response should detail the use of resources and assign only those resources needed to _________ the problem.

A)assess
B)quantify
C)delegate
D)fix
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
13
Each __________ needs a plan and a measured response spelled out in the disaster recovery plan.

A)assessment
B)recovery
C)threat
D)plan
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
14
The best disaster is the one you don't have to __________.

A)plan for
B)avoid
C)recover from
D)assess
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
15
The possibility of harm or loss from any given disaster is different depending on the __________.

A)organization
B)situation
C)severity of the disaster
D)All of the above
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
16
Realistic ramifications and weights should be assigned to all events and potential ______________.
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
17
A(n)__________ is anything that can cause harm.
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
18
Which of the following is among the most difficult to recover?

A)Microfilm
B)Paper
C)Computer disks
D)Hard drives
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
19
OCTAVE,a highly flexible assessment strategy,can be tailored to nearly any organization and can be very effective in identifying __________.

A)costs associated with disaster recovery
B)areas where the organization is most likely to be affected by a disaster recovery
C)areas where the organization is most likely to be affected by a disaster situation
D)areas where the organization is most likely to be affected by backup procedures
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
20
__________ is a risk-based strategic assessment and planning technique used primarily for security but which also can be used for disaster recovery planning purposes.

A)OCTAVE
B)Business Impact Analysis
C)Asset-based Risk Assessment
D)Disaster-based Risk Assessment
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
21
Functions need to be assessed by problems that their __________ will cause to the everyday operations of the business.
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
22
In __________ process,rather than identifying the assets and disasters and then driving the process from those perspectives,you address the whole organization from the perspective of the perceived threats.
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
23
For each asset that the company identifies,it needs to identify all the __________ that could impact each of the assets.
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
24
All disasters and emergencies have a(n)________________ impact.
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
25
A(n)__________ method of risk assessment needs to be applied across the business enterprise.
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
26
Match between columns
Risk
magnitude of the potential loss
Risk
result of judging the worth or value of something or someone
Risk
the possibility of suffering harm or loss because of an event
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
27
Match the following terms with their definitions:

-Business impact

A)magnitude of the potential loss
B)result of judging the worth or value of something or someone
C)the possibility of suffering harm or loss because of an event
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
28
Match the following terms with their definitions:

-Assessment

A)magnitude of the potential loss
B)result of judging the worth or value of something or someone
C)the possibility of suffering harm or loss because of an event
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
29
Match the following terms with there definitions:

-Disaster-based risk assessment

A)key to the ability to recover from disasters
B)based on awareness of existing risk factors
C)all possible hazards, rated
D)shows where the organization is in its disaster recovery process
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
30
Match the following terms with there definitions:

-Tracking document

A)key to the ability to recover from disasters
B)based on awareness of existing risk factors
C)all possible hazards, rated
D)shows where the organization is in its disaster recovery process
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
31
Match the following terms with there definitions:

-Accurately identified hazards

A)key to the ability to recover from disasters
B)based on awareness of existing risk factors
C)all possible hazards, rated
D)shows where the organization is in its disaster recovery process
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
32
Match the following terms with there definitions:

-Weighted hazard list

A)key to the ability to recover from disasters
B)based on awareness of existing risk factors
C)all possible hazards, rated
D)shows where the organization is in its disaster recovery process
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
33
Match each of the disaster-based risk assessment steps with its order of completion:

-First

A)assess hazards
B)implement controls
C)test and evaluate
D)identify hazards
E)develop controls and make risk decisions
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
34
Match each of the disaster-based risk assessment steps with its order of completion:

-Second

A)assess hazards
B)implement controls
C)test and evaluate
D)identify hazards
E)develop controls and make risk decisions
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
35
Match each of the disaster-based risk assessment steps with its order of completion:

-Third

A)assess hazards
B)implement controls
C)test and evaluate
D)identify hazards
E)develop controls and make risk decisions
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
36
Match each of the disaster-based risk assessment steps with its order of completion:

-Fourth

A)assess hazards
B)implement controls
C)test and evaluate
D)identify hazards
E)develop controls and make risk decisions
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
37
Match each of the disaster-based risk assessment steps with its order of completion:

-Fifth

A)assess hazards
B)implement controls
C)test and evaluate
D)identify hazards
E)develop controls and make risk decisions
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
38
Match the following terms to their descriptions:

-Service Level Agreement

A)role that each area in the organization plays
B)addresses the organization from the perspective of perceived threats
C)the level of harm that may occur from any given threat or risk
D)a contract that spells out the terms of service that will be provided
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
39
Match the following terms to their descriptions:

-Functional Area Input

A)role that each area in the organization plays
B)addresses the organization from the perspective of perceived threats
C)the level of harm that may occur from any given threat or risk
D)a contract that spells out the terms of service that will be provided
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
40
Match the following terms to their descriptions:

-Business Impact Analysis

A)role that each area in the organization plays
B)addresses the organization from the perspective of perceived threats
C)the level of harm that may occur from any given threat or risk
D)a contract that spells out the terms of service that will be provided
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
41
Match the following terms to their descriptions:

-Business Impact

A)role that each area in the organization plays
B)addresses the organization from the perspective of perceived threats
C)the level of harm that may occur from any given threat or risk
D)a contract that spells out the terms of service that will be provided
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
42
Match the following OCTAVE phases with their respective phase number:

-Phase 1

A)Identify Infrastructure Vulnerabilities
B)Develop a Security Strategy
C)Create a Threat Profile
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
43
Match the following OCTAVE phases with their respective phase number:

-Phase 2

A)Identify Infrastructure Vulnerabilities
B)Develop a Security Strategy
C)Create a Threat Profile
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
44
Match the following OCTAVE phases with their respective phase number:

-Phase 3

A)Identify Infrastructure Vulnerabilities
B)Develop a Security Strategy
C)Create a Threat Profile
Unlock Deck
Unlock for access to all 44 flashcards in this deck.
Unlock Deck
k this deck
locked card icon
Unlock Deck
Unlock for access to all 44 flashcards in this deck.