CASP+ Risk Management and Compliance 1 — Questions and Answers
Question 1: An organization must choose between accepting, transferring, mitigating, or avoiding a risk. Which option is MOST appropriate for a low-likelihood, low-impact risk where mitigation cost exceeds potential loss?
- Mitigate by implementing compensating controls
- Transfer via cyber liability insurance
- Accept the risk and document the decision (Correct answer)
- Avoid the risk by discontinuing the activity
Correct answer: Accept the risk and document the decision
When mitigation cost exceeds potential loss for a low-likelihood, low-impact risk, accepting the risk with documented rationale is the most cost-effective decision.
Question 2: Which metric BEST quantifies the financial impact of a single security incident for risk calculation purposes?
- Annualized Rate of Occurrence (ARO)
- Single Loss Expectancy (SLE) (Correct answer)
- Control gap score
- Residual risk percentage
Correct answer: Single Loss Expectancy (SLE)
SLE = Asset Value × Exposure Factor and represents the expected financial loss from a single occurrence of a specific threat event.
Question 3: A CASP+ professional conducts a BIA. Which output is MOST critical for defining recovery objectives?
- A list of all IT assets
- Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for each critical process (Correct answer)
- A full network topology diagram
- The organization's annual IT budget
Correct answer: Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for each critical process
RTO (maximum tolerable downtime) and RPO (maximum acceptable data loss) are the primary outputs of a BIA that drive continuity and recovery planning.
Question 4: Which compliance framework is MOST applicable to a US healthcare organization processing electronic protected health information (ePHI)?
- PCI DSS
- SOC 2 Type II
- HIPAA Security Rule (Correct answer)
- GDPR
Correct answer: HIPAA Security Rule
The HIPAA Security Rule mandates administrative, physical, and technical safeguards specifically for ePHI held by covered entities and business associates in the US.
Question 5: An organization wants to assess the maturity of its information security program. Which framework provides a structured maturity model for this purpose?
- CVE/NVD database
- CMMC (Cybersecurity Maturity Model Certification) (Correct answer)
- OWASP Top 10
- MITRE ATT&CK framework
Correct answer: CMMC (Cybersecurity Maturity Model Certification)
CMMC defines progressive maturity levels (1–3) with specific practice requirements, enabling organizations to benchmark and improve their cybersecurity posture.
Question 6: Which document formally authorizes an information system to operate and accepts residual risk on behalf of the organization?
- System Security Plan (SSP)
- Plan of Action and Milestones (POA&M)
- Authority to Operate (ATO) (Correct answer)
- Risk Assessment Report (RAR)
Correct answer: Authority to Operate (ATO)
An ATO is the official management decision by an authorizing official (AO) accepting the residual risk and granting permission for the system to operate.
An organization must choose between accepting, transferring, mitigating, or avoiding a risk.
Which option is MOST appropriate for a low-likelihood, low-impact risk where mitigation cost exceeds potential loss?