CND Risk Management & Compliance 3 — Questions and Answers
Question 1: Which NIST publication provides guidance specifically on the Risk Management Framework (RMF)?
- NIST SP 800-53
- NIST SP 800-37 (Correct answer)
- NIST SP 800-61
- NIST SP 800-171
Correct answer: NIST SP 800-37
NIST SP 800-37 describes the Risk Management Framework (RMF) for federal information systems, outlining six steps from categorization to continuous monitoring.
Question 2: An organization discovers a vulnerability but decides no action is needed because the cost of mitigation exceeds the asset's value. This decision is an example of:
- Risk transference
- Risk avoidance
- Risk acceptance (Correct answer)
- Risk mitigation
Correct answer: Risk acceptance
Risk acceptance (also called risk retention) occurs when management consciously chooses to accept a risk, often because mitigation costs outweigh potential loss.
Question 3: Which SOX section holds executives personally accountable for the accuracy of financial reports and the effectiveness of internal controls?
- Section 302 (Correct answer)
- Section 404
- Section 409
- Section 802
Correct answer: Section 302
SOX Section 302 requires CEOs and CFOs to personally certify the accuracy of financial statements and the effectiveness of internal controls.
Question 4: In a Business Impact Analysis (BIA), the Recovery Time Objective (RTO) defines:
- The maximum tolerable data loss measured in time
- The cost to restore operations after a disaster
- The maximum acceptable downtime before business impact becomes critical (Correct answer)
- The point in time to which data must be recovered
Correct answer: The maximum acceptable downtime before business impact becomes critical
RTO is the maximum acceptable length of time a system can be offline before the impact on the business becomes unacceptable.
Question 5: Which framework uses a five-function structure — Identify, Protect, Detect, Respond, Recover — for managing cybersecurity risk?
- ISO/IEC 27001
- NIST Cybersecurity Framework (CSF) (Correct answer)
- COBIT 5
- CIS Controls
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) organizes cybersecurity activities into five core functions: Identify, Protect, Detect, Respond, and Recover.
Question 6: A threat agent exploits a software vulnerability to gain unauthorized access. In risk terminology, what is the 'threat agent'?
- The weakness in the software
- The entity that takes advantage of the vulnerability (Correct answer)
- The impact of the successful attack
- The control designed to prevent exploitation
Correct answer: The entity that takes advantage of the vulnerability
A threat agent (or threat actor) is the person, group, or entity that initiates and carries out an attack by exploiting a vulnerability.
Question 7: Which GDPR principle requires that personal data be collected only for specified, explicit, and legitimate purposes?
- Data minimization
- Storage limitation
- Purpose limitation (Correct answer)
- Integrity and confidentiality
Correct answer: Purpose limitation
The GDPR principle of purpose limitation restricts organizations from using personal data for purposes beyond what was originally specified at collection.
Which NIST publication provides guidance specifically on the Risk Management Framework (RMF)?