CASP+ Risk Management and Compliance 2 — Questions and Answers
Question 1: Which risk treatment option is demonstrated when an organization purchases cyber liability insurance?
- Risk avoidance
- Risk mitigation
- Risk transference (Correct answer)
- Risk acceptance
Correct answer: Risk transference
Cyber liability insurance transfers the financial consequences of a risk to an insurance provider, though the operational risk remains with the organization.
Question 2: A vendor assessment reveals that a critical third-party provider has no incident response plan. Which contractual mechanism BEST addresses this risk?
- Requiring the vendor to self-certify compliance
- Including security requirements and audit rights in the contract (right-to-audit clause) (Correct answer)
- Terminating the contract immediately
- Accepting the risk as an inherent part of outsourcing
Correct answer: Including security requirements and audit rights in the contract (right-to-audit clause)
Contract clauses that specify security requirements and grant audit rights enable the organization to verify compliance and mandate remediation, providing enforceable protection.
Question 3: Which quantitative risk analysis technique uses probability distributions and repeated simulations to model the range of possible outcomes?
- CVSS scoring
- Monte Carlo simulation (Correct answer)
- DREAD model
- STRIDE threat modeling
Correct answer: Monte Carlo simulation
Monte Carlo simulation runs thousands of iterations with random values drawn from probability distributions to produce a range of risk outcomes and their likelihoods.
Question 4: An organization subject to GDPR must respond to a personal data breach notification requirement within what timeframe?
- 30 days of discovery
- 72 hours of becoming aware of the breach (if it poses a risk to individuals) (Correct answer)
- 7 business days
- 90 days of the end of fiscal quarter
Correct answer: 72 hours of becoming aware of the breach (if it poses a risk to individuals)
Article 33 of the GDPR requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach that poses a risk to individuals' rights.
Question 5: A CASP+ analyst applies threat modeling to a new application. Which methodology uses the mnemonic STRIDE to categorize threats?
- PASTA (Process for Attack Simulation and Threat Analysis)
- Microsoft STRIDE threat modeling (Correct answer)
- OCTAVE Allegro
- FAIR (Factor Analysis of Information Risk)
Correct answer: Microsoft STRIDE threat modeling
Microsoft's STRIDE model categorizes threats as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.
Question 6: Which metric represents the frequency with which a threat event is expected to occur in a given year?
- Single Loss Expectancy (SLE)
- Annualized Loss Expectancy (ALE)
- Annualized Rate of Occurrence (ARO) (Correct answer)
- Exposure Factor (EF)
Correct answer: Annualized Rate of Occurrence (ARO)
ARO is the estimated number of times a specific threat event is expected to occur per year, used to calculate ALE = SLE × ARO.
Which risk treatment option is demonstrated when an organization purchases cyber liability insurance?