4. Two of the activities involved in risk management include identifying risks and assessing risks. Which
of the following activities is part of the risk identification process?
Determining the likelihood that vulnerable systems will be attacked by specific threats
Calculating the risks to which assets are exposed in their current setting
Assigning a value to each information asset
Documenting and reporting the findings of risk identification and assessment
5. Which of the following is a network device attribute that may be used in conjunction with DHCP,
making asset-identification using this attribute difficult?
6. Which of the following is a network device attribute that is tied to the network interface?
7. Which of the following attributes does NOT apply to software information assets?
8. Which of the following distinctly identifies an asset and can be vital in later analysis of threats directed
to specific models of certain devices or software components?
Manufacturer’s part number
9. Asset classification schemes should categorize information assets based on which of the following?
cost and replacement value
sensitivity and security needs
ease of reproduction and fragility
10. Classification categories must be mutually exclusive and which of the following?
11. What is the final step in the risk identification process?
assessing values for information assets
identifying and inventorying assets
classifying and categorizing assets
listing assets in order of importance
12. Once an information asset is identified, categorized, and classified, what must also be assigned to it?