CCP Cybersecurity Principles & Risk Management 2 — Questions and Answers
Question 1: Which risk treatment option involves transferring the financial impact of a risk to a third party?
- Risk avoidance
- Risk acceptance
- Risk transference (Correct answer)
- Risk mitigation
Correct answer: Risk transference
Risk transference shifts the financial burden of a risk to another party, such as an insurance provider or outsourced vendor.
Question 2: What is the PRIMARY purpose of a Business Impact Analysis (BIA)?
- Identify threat actors targeting the organization
- Determine the criticality of business functions and recovery priorities (Correct answer)
- Audit IT asset inventories
- Assess vendor security posture
Correct answer: Determine the criticality of business functions and recovery priorities
A BIA identifies critical business processes, quantifies the impact of disruptions, and establishes Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
Question 3: An organization wants to ensure that no single employee can complete a high-risk transaction alone. Which principle does this implement?
- Least privilege
- Defense in depth
- Separation of duties (Correct answer)
- Need to know
Correct answer: Separation of duties
Separation of duties requires multiple individuals to complete a sensitive task, reducing the risk of fraud or error by any one person.
Question 4: In the NIST Cybersecurity Framework, which function focuses on developing and implementing appropriate safeguards to ensure delivery of critical services?
- Identify
- Protect (Correct answer)
- Detect
- Respond
Correct answer: Protect
The Protect function encompasses safeguards such as access control, awareness training, data security, and protective technology to limit the impact of cybersecurity events.
Question 5: What term describes a weakness in a system that can be exploited by a threat actor?
- Risk
- Threat
- Vulnerability (Correct answer)
- Impact
Correct answer: Vulnerability
A vulnerability is a flaw or weakness in a system, process, or control that could be exploited to compromise security.
Question 6: Which of the following BEST describes qualitative risk assessment?
- Uses exact dollar values to measure risk
- Relies on subjective ratings such as High, Medium, and Low (Correct answer)
- Calculates Annual Loss Expectancy mathematically
- Counts the number of vulnerabilities per system
Correct answer: Relies on subjective ratings such as High, Medium, and Low
Qualitative risk assessment uses descriptive scales and expert judgment rather than precise numerical values to evaluate and prioritize risks.
Question 7: A company decides not to launch a new internet-facing service because the associated security risks are too high. Which risk response is being applied?
- Risk mitigation
- Risk acceptance
- Risk avoidance (Correct answer)
- Risk transference
Correct answer: Risk avoidance
Risk avoidance involves eliminating the risk entirely by deciding not to engage in the activity that creates it.
Which risk treatment option involves transferring the financial impact of a risk to a third party?