100-160 exam dumps

100-160 practice question 199 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 199

Select 3

Your organization is planning to implement a new cloud-based application. During the planning phase, the cybersecurity team identifies potential risks such as unauthorized data access, system downtime, and compliance violations. As a cybersecurity technician, which steps should you recommend to effectively manage these risks?

  1. A

    Identify and classify assets to determine their criticality

  2. B

    Implement controls to mitigate or reduce identified risks

  3. C

    Accept all risks since they cannot be completely eliminated

  4. D

    Conduct regular risk assessments to evaluate new and existing risks

  5. E

    Transfer all risks to a third-party cloud provider to ensure full protection

Show answer and explanation

Correct answers: A, B, D

Explanation

Effective risk management involves a systematic approach that includes identifying and classifying assets, implementing controls to mitigate risks, and conducting regular risk assessments. While some risks may be transferred or accepted, these actions should be based on careful analysis, and responsibility for cybersecurity cannot be entirely outsourced. These steps collectively help organizations manage and minimize risks to their operations and data.

  • A. Correct.

    Identifying and classifying assets is a crucial step in understanding what needs protection and prioritizing efforts based on criticality. This is an essential component of risk management.

  • B. Correct.

    Implementing controls, such as technical, administrative, or physical measures, is necessary to mitigate or reduce the impact of identified risks.

  • C. Incorrect.

    Accepting all risks is not a best practice in cybersecurity. While some risks may be accepted based on cost-benefit analysis, it is not appropriate to accept all risks indiscriminately.

  • D. Correct.

    Conducting regular risk assessments ensures that new risks are identified and existing risks are reassessed, which is a critical part of maintaining an effective risk management strategy.

  • E. Incorrect.

    Transferring risks to a third-party provider, such as a cloud provider, may reduce some risks but does not ensure full protection. Responsibility for risk management cannot be completely outsourced.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam