CIM Risk Assessment & Mitigation 4 — Questions and Answers
Question 1: An incident manager discovers that a critical server has an open RDP port exposed to the internet. Using the risk equation Risk = Threat × Vulnerability × Impact, which variable does the open port MOST directly affect?
- Threat
- Vulnerability (Correct answer)
- Impact
- Likelihood is not part of this equation
Correct answer: Vulnerability
An open, exposed port is a vulnerability — a weakness that increases exploitability regardless of who the threat actor is.
Question 2: Which of the following BEST describes a 'black swan' event in risk management?
- A high-likelihood, low-impact routine incident
- A rare, high-impact event that was not predicted by historical models (Correct answer)
- A scheduled maintenance outage that causes unplanned downtime
- A risk that was deliberately accepted by senior management
Correct answer: A rare, high-impact event that was not predicted by historical models
Black swan events are characterized by extreme rarity, severe impact, and the tendency to be rationalized in hindsight as predictable.
Question 3: During a tabletop exercise, the team discovers their risk assessment missed a critical interdependency between two systems. This finding MOST directly highlights a gap in:
- Incident response playbooks
- Threat intelligence gathering
- Business impact analysis completeness (Correct answer)
- Patch management procedures
Correct answer: Business impact analysis completeness
Missed interdependencies between systems are a BIA gap — the analysis failed to map how one system's failure cascades to another.
Question 4: ISO 31000 recommends that risk management should be:
- Performed annually by the IT department as a standalone audit
- Integrated into all organizational processes and decision-making (Correct answer)
- Delegated entirely to external risk consultants
- Focused exclusively on financial and compliance risks
Correct answer: Integrated into all organizational processes and decision-making
ISO 31000 positions risk management as an integrated, ongoing organizational function embedded in all processes — not a periodic standalone activity.
Question 5: A Failure Mode and Effects Analysis (FMEA) assigns a Risk Priority Number (RPN) by multiplying three factors. Which combination is correct?
- Severity × Occurrence × Detection (Correct answer)
- Likelihood × Impact × Velocity
- Threat × Vulnerability × Asset Value
- Probability × Consequence × Exposure
Correct answer: Severity × Occurrence × Detection
FMEA RPN = Severity × Occurrence × Detection, where each factor is scored 1–10.
Question 6: When a risk treatment plan is documented, which element is MANDATORY to include for accountability purposes?
- A list of all stakeholders who reviewed the risk
- The named risk owner and target completion date for mitigation actions (Correct answer)
- The original threat intelligence source that identified the risk
- A sign-off from the organization's legal department
Correct answer: The named risk owner and target completion date for mitigation actions
A risk treatment plan must include an accountable owner and a deadline; without these, mitigation actions lack enforceability.
Question 7: Which approach to risk assessment relies on historical data, loss databases, and statistical models to assign numeric probabilities?
- Qualitative risk assessment
- Quantitative risk assessment (Correct answer)
- Semi-quantitative risk assessment
- Delphi method assessment
Correct answer: Quantitative risk assessment
Quantitative risk assessment uses objective numerical data — actuarial tables, incident history, and financial models — to calculate precise probability and impact values.
An incident manager discovers that a critical server has an open RDP port exposed to the internet.
Using the risk equation Risk = Threat × Vulnerability × Impact, which variable does the open port MOST directly affect?