0% found this document useful (0 votes)
40 views1 page

Cissp Q2

The document contains a series of questions and answers related to risk assessment methodologies and business continuity planning. It identifies OCTAVE as the qualitative risk assessment methodology and outlines the formula for calculating risk as 'Likelihood x Impact.' Additionally, it explains the purpose of a Business Impact Analysis and defines RTO as 'Recovery Time Objective.'
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
40 views1 page

Cissp Q2

The document contains a series of questions and answers related to risk assessment methodologies and business continuity planning. It identifies OCTAVE as the qualitative risk assessment methodology and outlines the formula for calculating risk as 'Likelihood x Impact.' Additionally, it explains the purpose of a Business Impact Analysis and defines RTO as 'Recovery Time Objective.'
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
You are on page 1/ 1

6. Which risk assessment methodology uses a qualitative approach?

o A) NIST SP 800-30
o B) OCTAVE
o C) ISO 27005
o D) FAIR

Answer: B) OCTAVE

7. What is the formula for calculating risk?


o A) Threat x Vulnerability x Cost of Impact
o B) Likelihood x Impact
o C) Exposure Factor x Single Loss Expectancy
o D) Annualized Rate of Occurrence x Single Loss Expectancy

Answer: B) Likelihood x Impact

Section 4: Business Continuity and Disaster Recovery Planning

8. What is the primary purpose of a Business Impact Analysis (BIA)?


o A) To identify the cause of security breaches
o B) To determine the potential impact of disruptions on business operations
o C) To evaluate the effectiveness of security policies
o D) To identify vulnerabilities in IT infrastructure

Answer: B) To determine the potential impact of disruptions on business operations

9. In disaster recovery planning, what does RTO stand for?


o A) Recovery Transfer Objective
o B) Risk Threshold Offset
o C) Recovery Time Objective
o D) Resilience Tracking Order

Answer: C) Recovery Time Objective

You might also like