CND Risk Management & Compliance 2 — Questions and Answers
Question 1: Which risk treatment option involves transferring the financial impact of a risk to a third party?
- Risk avoidance
- Risk acceptance
- Risk transference (Correct answer)
- Risk mitigation
Correct answer: Risk transference
Risk transference shifts the financial burden of a risk to another party, such as purchasing cyber insurance.
Question 2: In NIST SP 800-30, what is the correct order of the risk assessment process?
- Identify threats, identify vulnerabilities, determine likelihood, determine impact (Correct answer)
- Determine impact, identify threats, assess controls, determine likelihood
- Assess controls, identify threats, determine impact, identify vulnerabilities
- Identify vulnerabilities, determine impact, identify threats, assess controls
Correct answer: Identify threats, identify vulnerabilities, determine likelihood, determine impact
NIST SP 800-30 follows: identify threats, identify vulnerabilities, determine likelihood, then determine impact to derive overall risk.
Question 3: Which compliance framework specifically addresses the security of payment card data?
- HIPAA
- SOX
- PCI DSS (Correct answer)
- GLBA
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) mandates security controls for organizations that handle credit and debit card transactions.
Question 4: A quantitative risk analysis assigns monetary values to risk. What does the term 'Annual Loss Expectancy (ALE)' represent?
- The maximum possible loss from a single incident
- The product of SLE and ARO (Correct answer)
- The cost of implementing security controls
- The percentage chance a threat will occur in a year
Correct answer: The product of SLE and ARO
ALE = Single Loss Expectancy (SLE) × Annualized Rate of Occurrence (ARO), giving the expected yearly financial loss.
Question 5: Which document formally authorizes an information system to operate and accepts the residual risk?
- System Security Plan (SSP)
- Authority to Operate (ATO) (Correct answer)
- Risk Register
- Business Impact Analysis (BIA)
Correct answer: Authority to Operate (ATO)
An Authority to Operate (ATO) is issued by an authorizing official, formally accepting residual risk and permitting system operation.
Question 6: Under HIPAA, which rule specifically requires covered entities to implement administrative, physical, and technical safeguards for electronic PHI?
- Privacy Rule
- Breach Notification Rule
- Security Rule (Correct answer)
- Enforcement Rule
Correct answer: Security Rule
The HIPAA Security Rule requires covered entities to protect the confidentiality, integrity, and availability of electronic protected health information (ePHI).
Question 7: Which risk analysis method uses expert opinion and descriptive ratings such as 'High,' 'Medium,' and 'Low' rather than numerical values?
- Quantitative analysis
- Delphi method
- Qualitative analysis (Correct answer)
- Monte Carlo simulation
Correct answer: Qualitative analysis
Qualitative risk analysis uses subjective ratings and expert judgment instead of precise monetary or numerical calculations.
Which risk treatment option involves transferring the financial impact of a risk to a third party?