CCP Quantitative Risk Assessment 3 — Questions and Answers
Question 1: A financial institution uses Value at Risk (VaR) for cyber risk. A 99% VaR of $5 million means:
- Losses will never exceed $5 million
- There is a 1% chance losses will exceed $5 million in a given period (Correct answer)
- 99% of incidents cost exactly $5 million
- The organization will lose $5 million this year
Correct answer: There is a 1% chance losses will exceed $5 million in a given period
VaR at 99% confidence means there is a 1% probability that losses will exceed the stated amount in the defined period.
Question 2: When building a quantitative risk model, what is the primary purpose of using probability distributions (e.g., PERT, lognormal) for loss estimates?
- To eliminate uncertainty from calculations
- To capture the range and likelihood of different loss scenarios (Correct answer)
- To simplify calculations to a single number
- To comply with regulatory requirements
Correct answer: To capture the range and likelihood of different loss scenarios
Probability distributions capture the inherent uncertainty in loss estimates by modeling the full range of plausible outcomes.
Question 3: An organization experiences data breaches at an average rate of 0.5 times per year. Using the Poisson distribution, what is the probability of exactly zero breaches in a given year?
- 50%
- approximately 39%
- approximately 61% (Correct answer)
- approximately 78%
Correct answer: approximately 61%
P(0) = e^(-0.5) ≈ 0.6065, or about 61%, using the Poisson formula with λ=0.5.
Question 4: In the FAIR (Factor Analysis of Information Risk) model, what are the two primary components that combine to determine risk?
- Threat and vulnerability
- Loss event frequency and loss magnitude (Correct answer)
- Asset value and exposure factor
- Probability and impact
Correct answer: Loss event frequency and loss magnitude
FAIR defines risk as a function of Loss Event Frequency (how often) and Loss Magnitude (how much).
Question 5: A cyber risk analyst is told to use a 'minimum, most likely, maximum' approach for loss estimates. Which distribution does this describe?
- Normal distribution
- Poisson distribution
- PERT (Program Evaluation and Review Technique) distribution (Correct answer)
- Uniform distribution
Correct answer: PERT (Program Evaluation and Review Technique) distribution
PERT distribution uses minimum, most likely, and maximum values to model uncertain estimates with emphasis on the most likely value.
Question 6: What is the key difference between Tail Risk and average expected loss in cyber risk quantification?
- Tail risk measures past losses while average measures future losses
- Tail risk focuses on rare, high-severity loss events beyond a confidence threshold (Correct answer)
- Tail risk applies only to insider threats
- Average expected loss always exceeds tail risk
Correct answer: Tail risk focuses on rare, high-severity loss events beyond a confidence threshold
Tail risk captures catastrophic, low-probability events in the extreme end of a loss distribution beyond the VaR threshold.
Question 7: Which metric is most useful for comparing the cost-effectiveness of two different security controls in a quantitative risk assessment?
- Single Loss Expectancy (SLE)
- Return on Security Investment (ROSI) (Correct answer)
- Exposure Factor (EF)
- Mean Time to Recovery (MTTR)
Correct answer: Return on Security Investment (ROSI)
ROSI allows direct comparison of controls by measuring the net risk reduction relative to each control's cost.
A financial institution uses Value at Risk (VaR) for cyber risk.
A 99% VaR of $5 million means: