70-413 Exam Risk Assessment & Management 2 — Questions and Answers
Question 1: A company is designing a new Active Directory forest. Which risk mitigation strategy involves creating a separate forest for high-security resources to limit blast radius from a compromise?
- Risk transference
- Security boundary isolation (Correct answer)
- Risk acceptance
- Vulnerability scanning
Correct answer: Security boundary isolation
Creating a separate AD forest establishes a security boundary that contains potential compromises, limiting their impact to only that forest.
Question 2: During a risk assessment for a Windows Server 2012 R2 deployment, you identify that a critical patch cannot be applied due to a vendor-unsupported application. What is the BEST compensating control?
- Uninstall the application immediately
- Isolate the server on a restricted VLAN with enhanced monitoring (Correct answer)
- Accept the risk without any action
- Upgrade to Windows Server 2016
Correct answer: Isolate the server on a restricted VLAN with enhanced monitoring
Network isolation with enhanced monitoring is the best compensating control when a patch cannot be applied, reducing exposure while maintaining functionality.
Question 3: Which qualitative risk assessment method assigns risks to categories such as High, Medium, and Low based on likelihood and impact?
- Monte Carlo simulation
- Risk matrix (heat map) (Correct answer)
- Annual Loss Expectancy calculation
- Fault tree analysis
Correct answer: Risk matrix (heat map)
A risk matrix plots likelihood versus impact to categorize risks into qualitative levels like High, Medium, and Low.
Question 4: Your organization must comply with a regulation requiring encryption of all data at rest. You implement BitLocker on all servers. Which risk management concept does this represent?
- Risk avoidance
- Risk transfer
- Risk mitigation (Correct answer)
- Risk acceptance
Correct answer: Risk mitigation
Implementing BitLocker encryption reduces the impact of a data breach, which is an example of risk mitigation.
Question 5: A risk assessment identifies that a data center flood could destroy all servers. The company decides to purchase flood insurance. Which risk response strategy is this?
- Risk avoidance
- Risk acceptance
- Risk mitigation
- Risk transference (Correct answer)
Correct answer: Risk transference
Purchasing insurance transfers the financial consequences of a risk to a third party, which is risk transference.
Question 6: In quantitative risk analysis, what does the term 'Exposure Factor (EF)' represent?
- The total cost of deploying security controls
- The percentage of an asset's value lost in a single risk event (Correct answer)
- The number of times a threat is expected to occur per year
- The probability that a vulnerability will be exploited
Correct answer: The percentage of an asset's value lost in a single risk event
Exposure Factor (EF) is the percentage of the asset value that would be lost if a specific threat were realized.
Question 7: You are assessing risks for a Windows Server infrastructure migration. Which document formally authorizes the project team to proceed while acknowledging remaining residual risks?
- Business Impact Analysis
- Risk register
- Statement of Applicability
- Risk acceptance sign-off (acceptance letter) (Correct answer)
Correct answer: Risk acceptance sign-off (acceptance letter)
A formal risk acceptance sign-off documents that management acknowledges and accepts the residual risks associated with proceeding.
A company is designing a new Active Directory forest.
Which risk mitigation strategy involves creating a separate forest for high-security resources to limit blast radius from a compromise?