CIM Risk Assessment & Mitigation 2 — Questions and Answers
Question 1: A quantitative risk assessment assigns a risk score of 0.15 to a threat. Which formula was most likely used to calculate this value?
- Threat × Vulnerability × Asset Value
- Annual Loss Expectancy / Budget
- Single Loss Expectancy × Annualized Rate of Occurrence
- Impact × Likelihood on a 0–1 normalized scale (Correct answer)
Correct answer: Impact × Likelihood on a 0–1 normalized scale
A normalized 0–1 score is produced by multiplying probability (likelihood) by impact, both scaled to a 0–1 range.
Question 2: Which mitigation strategy is MOST appropriate when the cost of controlling a risk exceeds the value of the asset at risk?
- Risk avoidance
- Risk transfer
- Risk acceptance (Correct answer)
- Risk reduction
Correct answer: Risk acceptance
When control costs outweigh asset value, risk acceptance (knowingly tolerating the risk) is the rational economic choice.
Question 3: During a business impact analysis, the Recovery Point Objective (RPO) is best described as:
- The maximum time a system can be offline before business impact becomes unacceptable
- The point in time to which data must be restored after an incident (Correct answer)
- The minimum service level required during a degraded mode of operation
- The cost of recovering systems to full operational capacity
Correct answer: The point in time to which data must be restored after an incident
RPO defines the maximum age of data that must be recovered, determining backup frequency requirements.
Question 4: A threat agent exploits a known unpatched vulnerability in a web application. In risk terminology, the 'vulnerability' refers to:
- The motivation of the attacker
- A weakness that can be exploited to cause harm (Correct answer)
- The likelihood that an attack will succeed
- The financial impact of a successful breach
Correct answer: A weakness that can be exploited to cause harm
A vulnerability is a weakness or gap in protection that a threat agent can exploit.
Question 5: Which control type is specifically designed to DETECT risks after they have materialized?
- Preventive controls
- Detective controls (Correct answer)
- Corrective controls
- Compensating controls
Correct answer: Detective controls
Detective controls identify and alert on incidents or anomalies that have already occurred.
Question 6: An organization uses a 5×5 risk matrix. A risk rated 4 (high likelihood) × 5 (critical impact) is most appropriately managed by:
- Accepting the risk and monitoring quarterly
- Immediate escalation and priority mitigation (Correct answer)
- Transferring the risk to a third-party insurer
- Scheduling mitigation in the next annual planning cycle
Correct answer: Immediate escalation and priority mitigation
A score of 20/25 on a 5×5 matrix is a critical risk requiring immediate escalation and priority treatment.
Question 7: What is the PRIMARY purpose of a risk register in incident management?
- To document post-incident lessons learned
- To track identified risks, their scores, owners, and treatment status (Correct answer)
- To serve as the official incident log during active response
- To calculate financial reserves required for risk coverage
Correct answer: To track identified risks, their scores, owners, and treatment status
A risk register is a living document that records all identified risks along with their assessments, owners, and mitigation plans.
A quantitative risk assessment assigns a risk score of 0.15 to a threat.
Which formula was most likely used to calculate this value?