CISSP Security and Risk Management 2 — Questions and Answers
Question 1: Which risk treatment option involves sharing risk with a third party, such as through insurance or outsourcing?
- Risk avoidance
- Risk acceptance
- Risk transference (Correct answer)
- Risk mitigation
Correct answer: Risk transference
Risk transference shifts the financial burden of a risk to another party, such as purchasing cyber liability insurance.
Question 2: A company's ALE for a specific threat is $50,000 per year. A control costing $30,000 annually reduces the ALE to $10,000. What is the value of this control?
- $10,000
- $20,000 (Correct answer)
- $40,000
- $50,000
Correct answer: $20,000
Control value = (original ALE - residual ALE) - control cost = ($50,000 - $10,000) - $30,000 = $10,000, but the net risk reduction is $40,000 - $30,000 = $10,000; ALE reduction is $40,000 so value = $40,000 - $30,000 = $10,000.
Question 3: Which framework provides a structured approach to integrating security and privacy into the system development lifecycle using a risk management hierarchy of organization, mission, and system levels?
- COBIT 5
- NIST SP 800-37 RMF (Correct answer)
- ISO/IEC 27005
- OCTAVE Allegro
Correct answer: NIST SP 800-37 RMF
NIST SP 800-37 describes the Risk Management Framework (RMF) with a three-tier hierarchy spanning organization, mission/business process, and information system levels.
Question 4: Under the EU General Data Protection Regulation (GDPR), what is the maximum fine for the most serious violations?
- €10 million or 2% of global annual turnover
- €20 million or 4% of global annual turnover (Correct answer)
- $100 million or 5% of US revenue
- €50 million or 10% of EU revenue
Correct answer: €20 million or 4% of global annual turnover
GDPR Article 83(5) sets the maximum fine at €20 million or 4% of total worldwide annual turnover for the preceding year, whichever is higher.
Question 5: Which principle requires that personnel are granted only the permissions necessary to perform their specific job functions?
- Separation of duties
- Need to know
- Least privilege (Correct answer)
- Job rotation
Correct answer: Least privilege
Least privilege restricts user access rights to only what is required to perform authorized tasks, minimizing the attack surface.
Question 6: A Business Impact Analysis (BIA) is primarily used to:
- Identify all threats that could affect an organization
- Determine the criticality and recovery priorities of business functions (Correct answer)
- Calculate the annual loss expectancy for each asset
- Establish the organization's risk appetite
Correct answer: Determine the criticality and recovery priorities of business functions
A BIA identifies critical business functions, their dependencies, and establishes recovery time objectives (RTOs) and recovery point objectives (RPOs).
Question 7: Which type of law imposes obligations on organizations to protect personal data and can result in civil penalties paid to affected individuals?
- Criminal law
- Administrative law
- Tort law (civil law) (Correct answer)
- Contract law
Correct answer: Tort law (civil law)
Tort law allows individuals harmed by negligent data handling to sue for damages, making it a key driver of privacy obligations for organizations.
Which risk treatment option involves sharing risk with a third party, such as through insurance or outsourcing?