CCP CCP Risk Management & Assessment 2 — Questions and Answers
Question 1: What is the primary purpose of a Business Impact Analysis (BIA)?
- To identify all network vulnerabilities
- To determine critical business functions and their recovery priorities (Correct answer)
- To calculate the total cost of security controls
- To assess employee cybersecurity awareness levels
Correct answer: To determine critical business functions and their recovery priorities
A BIA identifies critical business functions, their dependencies, and the impact of disruptions to guide recovery prioritization.
Question 2: Which metric defines the maximum acceptable downtime for a system following a disaster?
- Recovery Point Objective (RPO)
- Mean Time to Repair (MTTR)
- Recovery Time Objective (RTO) (Correct answer)
- Maximum Tolerable Downtime (MTD)
Correct answer: Recovery Time Objective (RTO)
The Recovery Time Objective (RTO) specifies the maximum time allowed to restore a system or process after a disruption.
Question 3: In the NIST Risk Management Framework (RMF), which step involves choosing appropriate security controls?
- Categorize
- Select (Correct answer)
- Implement
- Assess
Correct answer: Select
The Select step in NIST RMF involves choosing security controls tailored to the system's risk categorization.
Question 4: Which type of risk assessment assigns numerical probabilities and financial values to risk outcomes?
- Qualitative
- Quantitative (Correct answer)
- Hybrid
- Subjective
Correct answer: Quantitative
Quantitative risk assessments use numerical data and monetary metrics to express risk in measurable financial terms.
Question 5: How is Annual Loss Expectancy (ALE) calculated?
- SLE divided by ARO
- SLE multiplied by ARO (Correct answer)
- ARO divided by asset value
- Asset value minus controls cost
Correct answer: SLE multiplied by ARO
ALE equals Single Loss Expectancy (SLE) multiplied by Annual Rate of Occurrence (ARO), representing expected yearly financial loss.
Question 6: When the cost of mitigating a risk exceeds the value of the asset at risk, which risk response is most appropriate?
- Risk transference
- Risk avoidance
- Risk acceptance (Correct answer)
- Risk mitigation
Correct answer: Risk acceptance
Risk acceptance is rational when the cost to mitigate a risk outweighs the potential financial loss from the risk event.
What is the primary purpose of a Business Impact Analysis (BIA)?