* Definition of a Risk Register * A risk register is a key tool in risk management used to document, track, and manage risks throughout their lifecycle. It serves as a central repository for all identified risks, detailing their nature, status, and potential impact. * Purpose of a Risk Register * The primary purpose is to maintain a log of discovered risks. It provides a structured approach to risk documentation, ensuring that all risks are identified, recorded, and available for review and analysis. * The risk register typically includes: * Risk descriptions. * Risk owners. * Likelihood and impact assessments. * Mitigation measures and actions. * Explanation of Options * A. Maintain a log of discovered risks:This is the correct answer. The risk register's main function is to act as a comprehensive inventory of risks, ensuring visibility and traceability across the organization. * B. Track individual risk assessments:While the risk register may include information from risk assessments, its primary purpose is not to track these assessments individually but to log and manage risks holistically. * C. Develop plans for mitigating identified risks:Risk mitigation plans are a separate output of the risk management process. The risk register may document these plans, but developing them is not its primary purpose. * D. Coordinate the timing of scheduled risk assessments:Scheduling risk assessments is part of the broader risk management process, not the primary function of the risk register. * EC-Council CISO Best Practices on Risk Management Tools * The framework advises using a risk register to: * Ensure a single source of truth for organizational risks. * Facilitate communication between stakeholders regarding risk priorities. * Support decision-making by providing a clear picture of the organization's risk landscape. * Serve as a foundation for regular updates, reviews, and audits of risk management activities. * Conclusion * The primary purpose of a risk register is A. Maintain a log of discovered risks. By centralizing risk information, it helps organizations manage risks effectively and ensures a transparent, documented approach to risk tracking.
Question 112
Your company has limited resources to spend on security initiatives. The Chief Financial Officer asks you to prioritize the protection of information resources based on their value to the company. It is essential that you be able to communicate in language that your fellow executives will understand. You should:
Correct Answer: D
Question 113
Which of the following represents the BEST method for obtaining business unit acceptance of security controls within an organization?
Correct Answer: C
Why Involvement Is Critical:Involving business units ensures that controls are practical, aligned with operational needs, and less likely to face resistance. Collaborative design fosters ownership and compliance. Key Considerations: * Engagement leads to tailored controls that support business processes without undue burden. * Promotes alignment between security objectives and business requirements. Why Not Other Options: * Allowing business units to decide controls (A) may lead to inconsistent security practices. * Creating separate controls (B) can increase complexity and reduce uniformity. * Mandating controls with audit schedules (D) enforces compliance but does not promote acceptance. EC-Council CISO Alignment:Collaborative control design reflects a mature and inclusive approach to security management.
Question 114
An anonymity network is a series of?
Correct Answer: D
Anonymity Networks:Anonymity networks, such as Tor (The Onion Router), rely on virtual network tunnels to mask users' IP addresses and activities by routing traffic through multiple encrypted nodes. Key Features: * Ensures anonymity by encrypting traffic between nodes. * Prevents tracking of source and destination. Why Not Other Options: * A. Covert government networks: Not specific to anonymity networks. * B. War driving maps: Associated with wireless network discovery, not anonymity. * C. Government networks in Tora: Misstatement; likely refers to Tor. EC-Council CISO Emphasis:Understanding anonymity networks is vital for cybersecurity professionals, both for defending against misuse and leveraging them for secure communication.
Question 115
During a cyber incident, which non-security personnel might be needed to assist the security team?
Correct Answer: A
* Non-Security Personnel for Incident Response: * Cyber incidents often require cross-functional collaboration. Non-security IT staff like network engineers, help desk technicians, and system administrators play critical roles in identifying, containing, and remediating incidents. * Network engineers: Analyze and secure affected network segments. * Help desk technicians: Handle end-user issues and initial incident reports. * System administrators: Investigate and secure affected systems. * Why Not Other Options: * A: These are security personnel, not non-security staff. * C: Executives like CIO, CFO, and CSO may oversee strategic responses but are not directly involved in technical containment. * D: Financial and HR personnel are unrelated to technical incident resolution. References: EC-Council CISO Handbook: Incident Response Team Composition and Roles.