CCP CCP Risk Management & Assessment 1 — Questions and Answers
Question 1: What is the standard formula for calculating risk in cybersecurity?
- Threat + Vulnerability
- Threat × Vulnerability × Asset Value (Correct answer)
- Asset Value / Threat
- Vulnerability - Threat
Correct answer: Threat × Vulnerability × Asset Value
Risk is commonly expressed as the product of threat likelihood, vulnerability severity, and asset value.
Question 2: Which risk treatment option involves shifting financial impact to a third party such as an insurer?
- Risk acceptance
- Risk avoidance
- Risk transference (Correct answer)
- Risk mitigation
Correct answer: Risk transference
Risk transference moves the financial consequences of a risk event to another party, such as through cyber insurance.
Question 3: What is residual risk?
- Risk completely eliminated by controls
- Risk remaining after security controls have been applied (Correct answer)
- The original risk before any assessment
- Risk associated only with third-party vendors
Correct answer: Risk remaining after security controls have been applied
Residual risk is the level of risk that persists after all security controls have been implemented.
Question 4: A qualitative risk assessment is best characterized by the use of:
- Exact monetary values
- Statistical probability tables
- Descriptive ratings such as High, Medium, and Low (Correct answer)
- Precise numerical formulas
Correct answer: Descriptive ratings such as High, Medium, and Low
Qualitative risk assessments use descriptive categories rather than precise numerical or financial values.
Question 5: What does Single Loss Expectancy (SLE) represent?
- The annual cost of all security controls
- The total value of all organizational assets
- The expected monetary loss from one occurrence of a specific risk event (Correct answer)
- The probability of a threat occurring within one year
Correct answer: The expected monetary loss from one occurrence of a specific risk event
SLE is the estimated dollar loss associated with a single occurrence of a given risk event.
Question 6: Which document formally authorizes a system to operate while acknowledging its residual risks?
- Security Assessment Report (SAR)
- Authorization to Operate (ATO) (Correct answer)
- Risk Management Plan
- System Security Plan (SSP)
Correct answer: Authorization to Operate (ATO)
An Authorization to Operate (ATO) is issued by an authorizing official who accepts the residual risks of a system.
What is the standard formula for calculating risk in cybersecurity?