ACI Risk Management & Mitigation 2 โ Questions and Answers
Question 1: During a digital forensic investigation, an examiner discovers that the suspect's hard drive is failing. Which risk mitigation step should be taken FIRST?
- Begin analysis immediately on the original drive
- Create a forensic image of the drive before it fails completely (Correct answer)
- Notify the suspect and request a replacement drive
- Document the failure and close the case
Correct answer: Create a forensic image of the drive before it fails completely
Creating a forensic image first preserves evidence before the drive fails, protecting evidentiary integrity.
Question 2: Which framework is most commonly referenced by ACI investigators when assessing organizational cybersecurity risk posture?
- ISO 9001
- NIST Cybersecurity Framework (CSF) (Correct answer)
- ITIL Service Management
- Six Sigma DMAIC
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST CSF provides a structured approach to identifying, protecting, detecting, responding to, and recovering from cybersecurity risks.
Question 3: A company experiences repeated phishing attacks targeting employees. Which risk mitigation strategy addresses the ROOT CAUSE most effectively?
- Install a more expensive firewall
- Conduct recurring security awareness training (Correct answer)
- Increase email storage quotas
- Disable all external email communication
Correct answer: Conduct recurring security awareness training
Security awareness training targets the human element, which is the root cause of phishing susceptibility.
Question 4: In risk management terminology, what does 'residual risk' refer to?
- The risk that existed before any controls were applied
- The risk remaining after controls and mitigations have been implemented (Correct answer)
- The risk transferred to a third-party insurer
- The risk eliminated through system upgrades
Correct answer: The risk remaining after controls and mitigations have been implemented
Residual risk is the level of risk that persists even after all planned risk mitigation controls have been applied.
Question 5: An ACI investigator recommends purchasing cyber liability insurance for a client. This is an example of which risk response strategy?
- Risk avoidance
- Risk acceptance
- Risk transference (Correct answer)
- Risk reduction
Correct answer: Risk transference
Purchasing insurance transfers the financial impact of a risk to a third party (the insurer).
Question 6: Which of the following BEST describes a 'threat actor' in the context of digital forensic risk assessment?
- A software vulnerability that can be exploited
- An individual or group with the capability and intent to cause harm (Correct answer)
- A hardware failure that leads to data loss
- A legal statute governing digital evidence
Correct answer: An individual or group with the capability and intent to cause harm
A threat actor is any entity โ individual, group, or organization โ with both motivation and capability to exploit vulnerabilities.
Question 7: When performing a risk assessment, what is the formula used to calculate risk level?
- Risk = Vulnerability ร Asset Value
- Risk = Threat ร Vulnerability ร Impact (Correct answer)
- Risk = Likelihood + Control Strength
- Risk = Impact รท Probability
Correct answer: Risk = Threat ร Vulnerability ร Impact
Risk is calculated by multiplying threat (likelihood of exploitation), vulnerability (weakness), and impact (consequence) together.
During a digital forensic investigation, an examiner discovers that the suspect's hard drive is failing.
Which risk mitigation step should be taken FIRST?