70-413 Exam Risk Assessment & Management 3 — Questions and Answers
Question 1: An organization uses a risk register to track identified risks. Which of the following fields is MOST important to include for effective risk monitoring over time?
- Risk owner and review date (Correct answer)
- Asset purchase price
- Vendor contact information
- Server hardware specifications
Correct answer: Risk owner and review date
Assigning a risk owner and a review date ensures accountability and periodic reassessment of each risk in the register.
Question 2: Which threat modeling methodology focuses on identifying Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege threats?
- PASTA
- STRIDE (Correct answer)
- DREAD
- OCTAVE
Correct answer: STRIDE
STRIDE is Microsoft's threat modeling framework that categorizes threats into six types for structured analysis.
Question 3: During risk assessment for a Hyper-V deployment, you determine that the likelihood of a VM escape attack is very low but the impact would be catastrophic. How should you prioritize this risk?
- Ignore it due to low likelihood
- Accept it as a residual risk
- Prioritize it highly because catastrophic impact overrides low likelihood (Correct answer)
- Deprioritize it and revisit quarterly
Correct answer: Prioritize it highly because catastrophic impact overrides low likelihood
Catastrophic impact risks must be prioritized regardless of low likelihood because the potential damage is severe and irreversible.
Question 4: What is the purpose of a Business Impact Analysis (BIA) in the context of risk management?
- To calculate the annual IT budget for security tools
- To identify critical business functions and the impact of disruptions to them (Correct answer)
- To enumerate all network vulnerabilities
- To document change management procedures
Correct answer: To identify critical business functions and the impact of disruptions to them
A BIA identifies critical business processes and quantifies the impact of disruptions, informing recovery priorities and risk decisions.
Question 5: A Windows Server administrator discovers an unpatched vulnerability with a CVSS score of 9.8. The affected server has no internet exposure and sits behind multiple firewall layers. Which risk factor does this layered defense address?
- Impact
- Vulnerability severity
- Threat likelihood/exploitability (Correct answer)
- Asset value
Correct answer: Threat likelihood/exploitability
Network isolation reduces the likelihood that a threat actor can exploit the vulnerability, even though its severity remains high.
Question 6: An organization wants to assess the risk of deploying a new PKI infrastructure. Which assessment technique involves systematically mapping out how failures can propagate through a system?
- Penetration testing
- Fault tree analysis (Correct answer)
- Vulnerability scanning
- Gap analysis
Correct answer: Fault tree analysis
Fault tree analysis uses a top-down diagram to identify how combinations of failures can lead to a system-level adverse event.
Question 7: When performing risk assessment for a server deployment, 'residual risk' is best defined as:
- The risk that existed before any controls were applied
- The risk that remains after security controls have been implemented (Correct answer)
- The maximum possible loss from a single incident
- The risk transferred to cyber insurance
Correct answer: The risk that remains after security controls have been implemented
Residual risk is the remaining level of risk after all planned security controls and mitigations have been implemented.
An organization uses a risk register to track identified risks.
Which of the following fields is MOST important to include for effective risk monitoring over time?