Cybersecurity Risk Management: Risk Mitigation and Control Implementation
This quiz assesses your understanding of risk mitigation and control implementation strategies in cybersecurity risk management.
Questions
Which of the following is NOT a common risk mitigation strategy?
- Implementing security controls
- Accepting the risk
- Transferring the risk
- Avoiding the risk
Which of the following is an example of a physical security control?
- Firewall
- Intrusion detection system
- Access control list
- Security guard
Which of the following is an example of a technical security control?
- Security policy
- Encryption
- Employee training
- Physical access control
Which of the following is an example of an administrative security control?
- Firewall
- Intrusion detection system
- Security policy
- Employee training
Which of the following is NOT a common risk control implementation challenge?
- Lack of resources
- Lack of expertise
- Lack of management support
- Lack of user awareness
Which of the following is a best practice for risk control implementation?
- Implement controls in a timely manner
- Prioritize controls based on risk
- Test controls regularly
- All of the above
Which of the following is a common risk control monitoring and evaluation activity?
- Reviewing logs and reports
- Conducting security audits
- Performing penetration testing
- All of the above
Which of the following is a benefit of risk control monitoring and evaluation?
- Improved security posture
- Reduced compliance risk
- Enhanced efficiency and effectiveness of controls
- All of the above
Which of the following is a common risk control reporting requirement?
- Sarbanes-Oxley Act (SOX)
- Payment Card Industry Data Security Standard (PCI DSS)
- Health Insurance Portability and Accountability Act (HIPAA)
- All of the above
Which of the following is a best practice for risk control reporting?
- Provide clear and concise information
- Use visuals to illustrate findings
- Tailor reports to the audience
- All of the above
Which of the following is a common risk control continuous improvement activity?
- Reviewing new and emerging threats
- Updating controls to address new risks
- Conducting regular risk assessments
- All of the above
Which of the following is a benefit of risk control continuous improvement?
- Improved security posture
- Reduced compliance risk
- Enhanced efficiency and effectiveness of controls
- All of the above
Which of the following is a common risk control maturity model?
- NIST Cybersecurity Framework (CSF)
- ISO 27001/27002
- COBIT
- All of the above
Which of the following is a benefit of using a risk control maturity model?
- Improved security posture
- Reduced compliance risk
- Enhanced efficiency and effectiveness of controls
- All of the above
Which of the following is a best practice for risk control governance?
- Establish a clear risk control governance structure
- Define roles and responsibilities for risk control
- Communicate risk control policies and procedures
- All of the above