CIM Risk Assessment & Mitigation 5 — Questions and Answers
Question 1: A healthcare organization identifies that ransomware attacks on similar hospitals have increased 40% year-over-year. This information is BEST classified as:
- Operational risk data
- Threat intelligence used to update risk likelihood scores (Correct answer)
- Residual risk documentation
- A compliance violation requiring immediate reporting
Correct answer: Threat intelligence used to update risk likelihood scores
Industry-wide attack trend data is threat intelligence that should feed back into the organization's risk likelihood assessments.
Question 2: The concept of 'defense in depth' in risk mitigation refers to:
- Deploying a single, highly effective control to eliminate a risk
- Layering multiple independent controls so that failure of one does not result in full exposure (Correct answer)
- Performing risk assessments at multiple organizational levels simultaneously
- Transferring risk to multiple insurance providers to spread financial exposure
Correct answer: Layering multiple independent controls so that failure of one does not result in full exposure
Defense in depth uses redundant, layered controls so an attacker must defeat multiple barriers, reducing the probability of a successful breach.
Question 3: An organization's risk appetite statement says 'we will not accept any risk with an impact score above 4 on our 5-point scale.' A new project introduces a risk scored 4/5 impact × 2/5 likelihood. The CORRECT action is:
- Accept the risk since likelihood is low
- Escalate for executive decision since impact exceeds the stated appetite threshold (Correct answer)
- Transfer the risk to the project vendor immediately
- Reduce the impact score by implementing a compensating control before proceeding
Correct answer: Escalate for executive decision since impact exceeds the stated appetite threshold
The impact of 4/5 exceeds the stated appetite ceiling; regardless of likelihood, this must be escalated per policy before proceeding.
Question 4: Which of the following is an example of a PROACTIVE risk mitigation action?
- Restoring from backup after a ransomware infection
- Patching a known vulnerability before it is exploited (Correct answer)
- Activating business continuity plans during an active outage
- Conducting a post-incident review to prevent recurrence
Correct answer: Patching a known vulnerability before it is exploited
Patching before exploitation prevents the risk from materializing, making it a proactive (preventive) mitigation.
Question 5: In the NIST Risk Management Framework (RMF), what is the purpose of the 'Categorize' step?
- To select appropriate security controls based on identified risks
- To classify information systems according to the potential impact of a security breach (Correct answer)
- To monitor the effectiveness of implemented controls over time
- To authorize system operation based on an acceptable risk determination
Correct answer: To classify information systems according to the potential impact of a security breach
The Categorize step in NIST RMF determines the system's security impact level (Low/Moderate/High) based on confidentiality, integrity, and availability impacts.
Question 6: A risk that has been transferred via cyber insurance still requires monitoring because:
- Insurance policies eliminate all residual risk exposure
- Coverage limits, exclusions, and insurer insolvency mean financial risk remains (Correct answer)
- Transferred risks no longer need to appear in the risk register
- Regulators prohibit relying on insurance as a risk treatment method
Correct answer: Coverage limits, exclusions, and insurer insolvency mean financial risk remains
Insurance policies have caps, exclusions, and conditions; transferred risk is not fully eliminated and residual financial exposure remains.
Question 7: Which metric measures the expected monetary loss from a specific threat over a one-year period?
- Single Loss Expectancy (SLE)
- Annual Loss Expectancy (ALE) (Correct answer)
- Mean Time Between Failures (MTBF)
- Recovery Time Objective (RTO)
Correct answer: Annual Loss Expectancy (ALE)
ALE = SLE × Annualized Rate of Occurrence, giving the expected average yearly financial loss from a particular threat.
A healthcare organization identifies that ransomware attacks on similar hospitals have increased 40% year-over-year.
This information is BEST classified as: