70-413 Exam Risk Assessment & Management 4 — Questions and Answers
Question 1: You are calculating Annual Loss Expectancy (ALE) for a server asset worth $200,000. The Exposure Factor is 50% and the Annualized Rate of Occurrence is 0.1. What is the ALE?
- $10,000 (Correct answer)
- $20,000
- $100,000
- $1,000
Correct answer: $10,000
ALE = SLE × ARO = ($200,000 × 0.5) × 0.1 = $100,000 × 0.1 = $10,000.
Question 2: Which risk management framework is specifically designed for IT systems and is published by NIST, making it widely used in US federal environments?
- ISO 27001
- COBIT 5
- NIST SP 800-30 (Correct answer)
- ITIL v4
Correct answer: NIST SP 800-30
NIST SP 800-30 provides guidelines for conducting risk assessments of federal information systems and organizations.
Question 3: An attacker gains access to a server through a known vulnerability that was already patched in a tested update. The patch was not deployed because the change management window hadn't opened. What risk category does this represent?
- Zero-day risk
- Operational/process risk (Correct answer)
- Physical security risk
- Supply chain risk
Correct answer: Operational/process risk
Failure to deploy a known patch due to a process delay is an operational risk, not a technical one — the fix existed but processes prevented its application.
Question 4: During a risk assessment workshop, stakeholders disagree about the probability of a particular threat. Which qualitative technique helps build consensus by iterating anonymous expert opinions until convergence?
- Delphi technique (Correct answer)
- Brainstorming
- Root cause analysis
- SWOT analysis
Correct answer: Delphi technique
The Delphi technique uses anonymous iterative rounds of expert input to reach consensus while avoiding groupthink.
Question 5: A risk assessment identifies that an unauthorized admin could disable Windows Firewall on critical servers. Implementing a Group Policy that prevents firewall modification is an example of which control type?
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
A Group Policy that prevents disabling the firewall proactively blocks the action from occurring, making it a preventive control.
Question 6: In the context of 70-413 designing a server infrastructure, which Hyper-V feature helps mitigate the risk of unauthorized VM sprawl and resource exhaustion?
- Dynamic Memory
- VM resource metering and quotas (Correct answer)
- Live Migration
- Replica (Hyper-V Replica)
Correct answer: VM resource metering and quotas
VM resource metering and quotas enforce limits on CPU, memory, and storage per VM, preventing any single VM from exhausting shared resources.
Question 7: A risk assessment recommends encrypting backup tapes stored off-site. An executive decides the cost outweighs the benefit and documents this decision. This is an example of:
- Risk mitigation
- Risk avoidance
- Risk acceptance (Correct answer)
- Risk transference
Correct answer: Risk acceptance
Formally deciding not to implement a control and documenting the decision is risk acceptance of the identified residual risk.
You are calculating Annual Loss Expectancy (ALE) for a server asset worth $200,000.
The Exposure Factor is 50% and the Annualized Rate of Occurrence is 0.1.
What is the ALE?