CCP Cybersecurity Principles & Risk Management 3 — Questions and Answers
Question 1: Which metric in quantitative risk analysis represents the expected monetary loss from a single occurrence of a threat event?
- Annual Rate of Occurrence (ARO)
- Annual Loss Expectancy (ALE)
- Single Loss Expectancy (SLE) (Correct answer)
- Exposure Factor (EF)
Correct answer: Single Loss Expectancy (SLE)
Single Loss Expectancy (SLE) is calculated as Asset Value multiplied by Exposure Factor, representing the cost of one occurrence of a specific threat.
Question 2: What is the role of a risk owner in a cybersecurity risk management program?
- Write technical patches for vulnerabilities
- Accept accountability for monitoring and managing an assigned risk (Correct answer)
- Conduct penetration tests on behalf of the organization
- Approve all IT procurement decisions
Correct answer: Accept accountability for monitoring and managing an assigned risk
A risk owner is an individual accountable for ensuring that an identified risk is monitored, treated appropriately, and reported as needed.
Question 3: Which concept describes the maximum level of risk an organization is prepared to accept in pursuit of its objectives?
- Risk threshold
- Risk appetite (Correct answer)
- Residual risk
- Inherent risk
Correct answer: Risk appetite
Risk appetite is the broad level of risk an organization is willing to accept before action is required, set by executive leadership and the board.
Question 4: After applying security controls, what term describes the risk that remains?
- Inherent risk
- Gross risk
- Residual risk (Correct answer)
- Secondary risk
Correct answer: Residual risk
Residual risk is the level of risk remaining after security controls and mitigations have been applied to the inherent risk.
Question 5: Which framework is MOST commonly used by US federal agencies for risk management and security authorization?
- ISO/IEC 27001
- COBIT 2019
- NIST RMF (SP 800-37) (Correct answer)
- CIS Controls v8
Correct answer: NIST RMF (SP 800-37)
The NIST Risk Management Framework (RMF), described in SP 800-37, provides a structured process for integrating security into federal information systems and is mandated for US federal agencies.
Question 6: An attacker intercepts a communication and secretly reads the data without altering it. Which security property is PRIMARILY violated?
- Integrity
- Availability
- Confidentiality (Correct answer)
- Non-repudiation
Correct answer: Confidentiality
Confidentiality ensures that information is accessible only to those authorized to access it; passive eavesdropping attacks violate this property.
Question 7: What is the MAIN difference between a policy and a standard in an information security governance framework?
- Policies are technical; standards are managerial
- Policies state high-level intent; standards define specific mandatory requirements (Correct answer)
- Standards are optional; policies are mandatory
- Policies apply to vendors; standards apply only to employees
Correct answer: Policies state high-level intent; standards define specific mandatory requirements
Policies express organizational intent and direction at a high level, while standards provide specific, mandatory requirements for implementing those policies.
Which metric in quantitative risk analysis represents the expected monetary loss from a single occurrence of a threat event?