Within the realm of IT security, which of the following combinations best defines risk?
A. Vulnerability coupled with an attack
B. Threat coupled with a breach of security
C. Threat coupled with a breach
D. Threat coupled with a vulnerability
Answer: D
The_answer: Threat coupled with a vulnerability. Threats are circumstances or actions with the ability to harm a system. They can destroy or modify data or result an a
DoS. Threats by themselves are not acted upon unless there is a vulnerability that can be taken advantage of. Risk enters the equation when a vulnerability (Flaw or weakness) exists in policies, procedures, personnel management, hardware, software or facilities and can be exploited by a threat agent. Vulnerabilities do not cause harm, but they leave the system open to harm. The combination of a threat with a vulnerability increases the risk to the system of an intrusion.
The following answers are incorrect:
Threat coupled with a breach. A threat is the potential that a particular threat-source will take advantage of a vulnerability. Breaches get around security. It does not matter if a breach is discovered or not, it has still occured and is not a risk of something occuring. A breach would quite often be termed as an incident or intrusion.
Vulnerability coupled with an attack. Vulnerabilities are weaknesses (flaws) in policies, procedures, personnel management, hardware, software or factilities that may result in a harmful intrusion to an IT system. An attack takes advantage of the flaw or vulnerability.
Attacks are explicit attempts to violate security, and are more than risk as they are active.
Threat coupled with a breach of security. This is a detractor. Although a threat agent may take advantage of (Breach) vulnerabilities or flaws in systems security. A threat coupled with a breach of security is more than a risk as this is active.
The following reference(s) may be used to research the topics in this question:
ISC2 OIG, 2007 p. 66-67
Shon Harris AIO v3 p. 71-72

Click on the calculator icon in the upper left-hand corner. Your customer wants to use a VNX system at an unmanned DR site. The system will be used exclusively as a secondary MirrorView/A system, and it is capable of performing 60,000 LUN IOPs in this role. The primary system is also a VNX.
If the total primary image workload consists of 1 KiB random I/Os with a R/W ratio of 3:1, what is the maximum bandwidth required for the link between the VNX systems?
A. 600 Mb/s
B. 240 Mb/s
C. 360 Mb/s
D. 120 Mb/s
Answer: B

An administrator has a backup for client Linux1 using the LinuxClients policy complete successfully. Even though the policy Backup Selections are NOT modified, the backup job fails the next day with the following status code:
Error 71: none of the files in the file list exist.
What is a possible reason the job failed?
A. The "Enable granular recovery" option was unset.
B. The client was added to another backup policy.
C. The client was temporarily shut down.
D. The file systems have been unmounted on the client.
Answer: D

Gut geschriebene Richtlinien zur Risikobewertung für die IS-Prüfung sollten mindestens angeben, welches der folgenden Elemente gilt (alle zutreffenden auswählen):
A. Keine der Auswahlmöglichkeiten.
B. Richtlinien für die Behandlung von Sonderfällen.
C. Eine maximale Länge für Überwachungszyklen.
D. Dokumentationsanforderungen.
E. Der Zeitpunkt der Risikobewertung.
Answer: B,C,D,E
In gut verfassten Richtlinien zur Risikobewertung sollte eine maximale Länge für Prüfungszyklen festgelegt werden, die auf den Risikobewertungen und dem Zeitpunkt der Risikobewertungen für jede Abteilung oder Aktivität basiert. Es sollte Dokumentationsanforderungen geben, um Bewertungsentscheidungen zu unterstützen. Es sollte auch Leitlinien für die vorrangige Risikobewertung in besonderen Fällen und für die Umstände geben, unter denen sie außer Kraft gesetzt werden können.


