CISSP Security and Risk Management 3 — Questions and Answers
Question 1: Which security planning document defines the acceptable level of loss that an organization is willing to tolerate?
- Risk register
- Risk appetite statement (Correct answer)
- Business impact analysis
- Security baseline
Correct answer: Risk appetite statement
A risk appetite statement formally documents the amount and type of risk an organization is willing to accept in pursuit of its objectives.
Question 2: The concept that no single person should have complete control over a critical process is known as:
- Least privilege
- Need to know
- Defense in depth
- Separation of duties (Correct answer)
Correct answer: Separation of duties
Separation of duties divides critical tasks among multiple individuals to prevent fraud and error by ensuring no one person can complete a harmful act alone.
Question 3: Which US federal law specifically requires federal agencies to protect information systems and mandates FISMA compliance?
- HIPAA
- GLBA
- Federal Information Security Modernization Act (FISMA) (Correct answer)
- Sarbanes-Oxley Act
Correct answer: Federal Information Security Modernization Act (FISMA)
FISMA requires federal agencies to develop, document, and implement agency-wide programs to provide information security for their systems.
Question 4: A qualitative risk assessment differs from a quantitative one in that it:
- Always produces more accurate results
- Uses numerical monetary values for all calculations
- Relies on expert judgment and descriptive categories like High/Medium/Low (Correct answer)
- Is only applicable to physical security risks
Correct answer: Relies on expert judgment and descriptive categories like High/Medium/Low
Qualitative risk assessments use subjective ratings and expert judgment rather than precise monetary calculations, making them faster but less precise.
Question 5: Which term describes the remaining risk after safeguards and controls have been applied?
- Inherent risk
- Total risk
- Residual risk (Correct answer)
- Control risk
Correct answer: Residual risk
Residual risk is the leftover risk exposure after all planned countermeasures have been implemented and accepted by management.
Question 6: Under GDPR, which role is responsible for giving instructions to the data processor and determining the purposes and means of processing personal data?
- Data processor
- Data subject
- Data controller (Correct answer)
- Data protection officer
Correct answer: Data controller
The data controller determines why and how personal data is processed and bears primary legal responsibility for GDPR compliance.
Question 7: Which threat modeling methodology focuses on identifying threats using attacker-centric categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?
- PASTA
- VAST
- STRIDE (Correct answer)
- DREAD
Correct answer: STRIDE
STRIDE, developed by Microsoft, categorizes threats into six types and is widely used to systematically identify security threats during design.
Which security planning document defines the acceptable level of loss that an organization is willing to tolerate?