Unit6 - Subjective Questions

INT242 • Practice Questions with Detailed Answers

1

Define Risk Management and explain the four main phases of the Risk Management Lifecycle.

2

Differentiate between Quantitative and Qualitative Risk Assessment.

3

Explain the relationship between Asset, Threat, Vulnerability, and Risk using a mathematical expression. Define each term.

4

Describe the four common risk response strategies: Avoidance, Acceptance, Transference, and Mitigation.

5

What is Supply Chain Risk Management (SCRM) and why is it crucial in Vendor Management?

6

Explain the Vendor Lifecycle Management process from a security perspective.

7

Distinguish between a Security Audit and a Security Assessment.

8

Compare Internal Audits and External Audits.

9

What is Data Classification? Describe a typical commercial data classification scheme.

10

Explain the concept of Data Loss Prevention (DLP) and its three states of data protection.

11

Discuss the importance of GDPR (General Data Protection Regulation) and list three of its key principles.

12

Explain the concept of 'Separation of Duties' and 'Least Privilege' in the context of Personnel Policies.

13

Why are 'Job Rotation' and 'Mandatory Vacation' considered security controls?

14

Describe the Onboarding and Offboarding processes for employees regarding cybersecurity.

15

What is the 'Zero Trust' model in modern security governance? List its core tenets.

16

How has the trend of Remote Work impacted Security Governance and what policies are needed to address it?

17

Explain the concept of Data Sovereignty and its relevance in cloud computing compliance.

18

Calculate the Annualized Loss Expectancy (ALE) if an asset is valued at $100,000, the Exposure Factor (EF) is 50%, and the Annualized Rate of Occurrence (ARO) is 0.1 (once every 10 years). Show the formula.

19

Discuss the role of Artificial Intelligence (AI) in modern Risk Management.

20

Write a short note on 'Shadow IT' and the risks associated with it.