Cybersecurity Risk Management: Risk Mitigation and Control Implementation

This quiz assesses your understanding of risk mitigation and control implementation strategies in cybersecurity risk management.

15 Questions Published

Questions

Question 1 Multiple Choice (Single Answer)

Which of the following is NOT a common risk mitigation strategy?

  1. Implementing security controls
  2. Accepting the risk
  3. Transferring the risk
  4. Avoiding the risk
Question 2 Multiple Choice (Single Answer)

Which of the following is an example of a physical security control?

  1. Firewall
  2. Intrusion detection system
  3. Access control list
  4. Security guard
Question 3 Multiple Choice (Single Answer)

Which of the following is an example of a technical security control?

  1. Security policy
  2. Encryption
  3. Employee training
  4. Physical access control
Question 4 Multiple Choice (Single Answer)

Which of the following is an example of an administrative security control?

  1. Firewall
  2. Intrusion detection system
  3. Security policy
  4. Employee training
Question 5 Multiple Choice (Single Answer)

Which of the following is NOT a common risk control implementation challenge?

  1. Lack of resources
  2. Lack of expertise
  3. Lack of management support
  4. Lack of user awareness
Question 6 Multiple Choice (Single Answer)

Which of the following is a best practice for risk control implementation?

  1. Implement controls in a timely manner
  2. Prioritize controls based on risk
  3. Test controls regularly
  4. All of the above
Question 7 Multiple Choice (Single Answer)

Which of the following is a common risk control monitoring and evaluation activity?

  1. Reviewing logs and reports
  2. Conducting security audits
  3. Performing penetration testing
  4. All of the above
Question 8 Multiple Choice (Single Answer)

Which of the following is a benefit of risk control monitoring and evaluation?

  1. Improved security posture
  2. Reduced compliance risk
  3. Enhanced efficiency and effectiveness of controls
  4. All of the above
Question 9 Multiple Choice (Single Answer)

Which of the following is a common risk control reporting requirement?

  1. Sarbanes-Oxley Act (SOX)
  2. Payment Card Industry Data Security Standard (PCI DSS)
  3. Health Insurance Portability and Accountability Act (HIPAA)
  4. All of the above
Question 10 Multiple Choice (Single Answer)

Which of the following is a best practice for risk control reporting?

  1. Provide clear and concise information
  2. Use visuals to illustrate findings
  3. Tailor reports to the audience
  4. All of the above
Question 11 Multiple Choice (Single Answer)

Which of the following is a common risk control continuous improvement activity?

  1. Reviewing new and emerging threats
  2. Updating controls to address new risks
  3. Conducting regular risk assessments
  4. All of the above
Question 12 Multiple Choice (Single Answer)

Which of the following is a benefit of risk control continuous improvement?

  1. Improved security posture
  2. Reduced compliance risk
  3. Enhanced efficiency and effectiveness of controls
  4. All of the above
Question 13 Multiple Choice (Single Answer)

Which of the following is a common risk control maturity model?

  1. NIST Cybersecurity Framework (CSF)
  2. ISO 27001/27002
  3. COBIT
  4. All of the above
Question 14 Multiple Choice (Single Answer)

Which of the following is a benefit of using a risk control maturity model?

  1. Improved security posture
  2. Reduced compliance risk
  3. Enhanced efficiency and effectiveness of controls
  4. All of the above
Question 15 Multiple Choice (Single Answer)

Which of the following is a best practice for risk control governance?

  1. Establish a clear risk control governance structure
  2. Define roles and responsibilities for risk control
  3. Communicate risk control policies and procedures
  4. All of the above