CIM Risk Assessment & Mitigation 3 — Questions and Answers
Question 1: Which scenario BEST illustrates the concept of 'residual risk'?
- A risk that has been fully eliminated through preventive controls
- The risk remaining after all mitigation measures have been applied (Correct answer)
- A newly identified risk that has not yet been assessed
- A risk that was transferred to an insurance provider
Correct answer: The risk remaining after all mitigation measures have been applied
Residual risk is the exposure that remains after controls and mitigations have been applied to the inherent risk.
Question 2: A CIM professional is conducting a risk assessment and needs to prioritize risks for treatment. Which criterion should be applied FIRST?
- The ease of implementing the mitigation control
- The combination of likelihood and impact scores (Correct answer)
- The age of the identified risk
- The political sensitivity of the affected department
Correct answer: The combination of likelihood and impact scores
Risk prioritization is fundamentally based on the product of likelihood and impact, identifying which risks pose the greatest overall threat.
Question 3: An organization mandates that all third-party vendors complete a security questionnaire before contract award. This is an example of:
- Risk avoidance
- Supply chain risk mitigation (Correct answer)
- Corrective control implementation
- Residual risk acceptance
Correct answer: Supply chain risk mitigation
Vetting vendors through security questionnaires is a proactive supply chain risk mitigation practice.
Question 4: When applying the DREAD risk scoring model, which of the following is NOT one of the five scoring categories?
- Damage potential
- Reproducibility
- Exploitability
- Asset criticality (Correct answer)
Correct answer: Asset criticality
DREAD stands for Damage, Reproducibility, Exploitability, Affected users, and Discoverability — asset criticality is not a DREAD dimension.
Question 5: In the context of risk treatment, 'risk transfer' is MOST effectively achieved through:
- Implementing technical controls to reduce likelihood
- Purchasing cyber liability insurance or outsourcing to a third party (Correct answer)
- Discontinuing the business activity that generates the risk
- Accepting the risk and documenting it in the risk register
Correct answer: Purchasing cyber liability insurance or outsourcing to a third party
Risk transfer shifts the financial consequences of a risk to another party, typically via insurance or contractual agreements.
Question 6: Which threat modeling framework categorizes threats into Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?
- OCTAVE
- STRIDE (Correct answer)
- PASTA
- FAIR
Correct answer: STRIDE
STRIDE is a Microsoft-developed threat modeling framework using six threat categories as its mnemonic.
Question 7: A risk owner is PRIMARILY responsible for:
- Implementing all technical controls related to the risk
- Making decisions about risk treatment and ensuring mitigation actions are completed (Correct answer)
- Conducting the initial risk identification and scoring
- Reporting residual risk to external regulators
Correct answer: Making decisions about risk treatment and ensuring mitigation actions are completed
The risk owner has accountability for deciding how the risk is treated and ensuring that agreed mitigation actions are executed.
Which scenario BEST illustrates the concept of 'residual risk'?