To specify security requirements, one should identify the risks that are to be dealt with ?
		A. True
B. False
Explanation: To specify security requirements, one should identify the assets that are to be dealt with.
		A. True
B. False
Explanation: To specify security requirements, one should identify the assets that are to be dealt with.
		A. Attack
B. Threat
C. Vulnerability
D. Control
Explanation: The answer is self explanatory.
		A. Controls that are intended to ensure that attacks are unsuccessful
B. Controls that are intended to detect and repel attacks
C. Controls that are intended to support recovery from problems
D. All of the mentioned
Explanation: All the options define a security control property.
		A. risk
B. control
C. attack
D. asset
Explanation: A control protective measure that reduces a system’s vulnerability.
		A. Storage management faults
B. Data Faults
C. Input/Output Faults
D. Interface faults
		A. Vulnerability
B. Attack
C. Threat
D. Exposure
		A. Fault Avoidance
B. Fault detection
C. Fault tolerance
D. None of the mentioned
Explanation: In Fault Avoidance, the system is developed in such a way that human error is avoided and thus system faults are minimised.