2.1.E.2Risk avoidance stops the activity that is generating the risk. If the activity is a critical part of an organization’s mission or purpose, then avoidance is not possible.Learning objective: Identify strategies for managing risk.
4.1.C.1Adversaries can develop exploits for known vulnerabilities in software (including operating systems). Devices with unpatched software are vulnerable to these exploits, which could allow an adversary to crash a system, view…Learning objective: Explain how adversaries can exploit common device vulnerabilities to cause loss, damage, disruption, or destruction.
4.1.C.6Adversaries can send malicious data to devices to disrupt them or attempt to take control of them. Devices that have no firewall (or a misconfigured firewall) cannot filter out this malicious data.Learning objective: Explain how adversaries can exploit common device vulnerabilities to cause loss, damage, disruption, or destruction.
AP Networking alignment
4.1.A.5When availability is compromised, systems have unexpected periods of time when they are out of service. A breach of availability can be identified by: • an inability to access systems, networks, or resources • slow or dropped…Learning objective: Identify evidence of compromised confidentiality, integrity, or availability.
4.5.B.1Organizations apply a combination of security controls to reduce the impact of different types of vulnerabilities. To determine appropriate security controls, administrators evaluate the likelihood and impact of specific…Learning objective: Determine appropriate security controls to limit the impacts of common threats and vulnerabilities in a managed network.
4.6.B.4Applying and documenting software updates and patches reduces the risk of failure and reduces recovery time if an outage occurs.Learning objective: Identify ways to improve the reliability and availability of networked systems.