A company stores highly sensitive military design data on an unencrypted drive that can be accessed by multiple employees. What is the overall risk level?
A small business stores customer names and email addresses in a password-protected file with basic encryption. What is the most appropriate risk level?
An organization stores internal meeting notes on a shared drive with no access controls. The notes do not contain sensitive information. What is the most appropriate risk level?
A company database containing payment card information is vulnerable to SQL injection attacks. What is the most likely overall risk level?
A system stores public product descriptions that are accessible to anyone, and the system has weak access controls. What is the most likely impact level?
A vulnerability allows an attacker to delete files from a system, preventing users from accessing them. Which aspect of security is primarily affected?
An attacker modifies records in a company database without authorization. Which aspect of security is compromised?
A hacker gains unauthorized access to view sensitive employee records. Which aspect of security is compromised?
A company uses strong encryption and strict access controls to protect sensitive data. How does this most directly affect risk?
Which combination is most likely to result in a high-risk vulnerability?
A company stores customer PII using weak encryption. What is the most appropriate risk level?
Which situation represents a moderate risk?
A company stores highly sensitive data but has very strong security protections in place. What is the most likely likelihood level?
Which statement best describes risk?
A system with weak access controls allows many users to edit important data. What is the most likely impact?
A vulnerability is difficult to exploit but would cause severe damage if successful. What is the most appropriate overall risk level?
A vulnerability is easy to exploit but only affects non-sensitive data. What is the most appropriate overall risk level?
Which situation would most likely result in a confidentiality breach?
Which situation would most likely result in an availability issue?
A company prioritizes fixing vulnerabilities that are both highly damaging and easy to exploit. What concept are they applying?