Instiq

5Practice (Exam B)

Practice questions →Glossary →
  • 5.1Risk Assessment in Practice

    Learn, through concrete organizational scenarios, how to identify and classify information assets in the field, calculate risk values (threat x vulnerability x asset value), set risk acceptance criteria, and build a response plan (mitigation, retention, avoidance, transfer) for the calculated risk.

  • 5.2Vendor and Supply Chain Management

    Learn, through concrete outsourcing scenarios, vendor selection and security requirements in contracts, managing re-subcontracting, the division of responsibility when using cloud services (the shared responsibility model), how to embed security requirements into an SLA, and audit and reporting obligations for vendors.

  • 5.3Security Education, Training, and Rule Operation

    Learn, through concrete organizational scenarios, how to design employee education, run and evaluate targeted-attack drills, thoroughly communicate rules and procedures, handle onboarding/offboarding procedures (account issuance and privilege revocation), respond to rule violations, and raise organization-wide security awareness.

  • 5.4Incident Response in Practice

    Learn, through a concrete incident response scenario, the flow of detection, initial response, containment, eradication, recovery, and post-incident activity, reporting and public communication, evidence preservation, recurrence prevention, and notification to relevant authorities (such as JPCERT/CC).