CND Risk Management & Compliance 4 — Questions and Answers
Question 1: Which step of the NIST RMF involves categorizing information systems based on the potential impact of a security breach?
- Select
- Implement
- Categorize (Correct answer)
- Authorize
Correct answer: Categorize
The Categorize step uses FIPS 199 and NIST SP 800-60 to classify systems based on the potential impact (low, moderate, high) of a confidentiality, integrity, or availability breach.
Question 2: An organization wants to comply with ISO/IEC 27001. Which document serves as the foundation by defining the scope, objectives, and boundaries of the Information Security Management System (ISMS)?
- Statement of Applicability (SoA) (Correct answer)
- Risk Treatment Plan
- Asset Inventory
- Information Security Policy
Correct answer: Statement of Applicability (SoA)
The Statement of Applicability (SoA) documents which ISO/IEC 27001 Annex A controls are applicable and justified for the organization's ISMS scope.
Question 3: During a risk assessment, an analyst finds that a web server is exposed to SQL injection. The vulnerability is the weakness, and the threat is malicious input. What is the 'risk' in this scenario?
- The firewall protecting the server
- The probability that the SQL injection succeeds combined with the resulting impact (Correct answer)
- The web server hardware itself
- The database administrator's lack of awareness
Correct answer: The probability that the SQL injection succeeds combined with the resulting impact
Risk is the combination of the likelihood that a threat exploits a vulnerability and the potential impact of that exploitation.
Question 4: Which compliance regulation applies to US financial institutions and requires them to protect the security and confidentiality of customer financial information?
- FERPA
- GLBA (Correct answer)
- COPPA
- FISMA
Correct answer: GLBA
The Gramm-Leach-Bliley Act (GLBA) requires US financial institutions to implement safeguards to protect nonpublic personal financial information.
Question 5: In risk management, the 'residual risk' is best described as:
- Risk that has been completely eliminated by security controls
- Risk that remains after security controls have been applied (Correct answer)
- The initial risk before any assessment is conducted
- Risk transferred to a third-party insurer
Correct answer: Risk that remains after security controls have been applied
Residual risk is the level of risk that remains after risk mitigation controls have been implemented; it must be accepted by management.
Question 6: Which federal law mandates that US government agencies implement information security programs and report to OMB annually?
- HIPAA
- SOX
- FISMA (Correct answer)
- FERPA
Correct answer: FISMA
The Federal Information Security Modernization Act (FISMA) requires federal agencies to develop, document, and implement agency-wide information security programs.
Question 7: A penetration testing company is hired to assess a client's network. Before testing begins, a document is signed that defines the scope, rules of engagement, and legal authorization. This document is called a:
- Non-Disclosure Agreement (NDA)
- Rules of Engagement (RoE) / Statement of Work (Correct answer)
- Risk Register
- Memorandum of Understanding (MOU)
Correct answer: Rules of Engagement (RoE) / Statement of Work
The Rules of Engagement (RoE) or Statement of Work defines the authorized scope, methods, and boundaries for penetration testing, providing legal protection.
Which step of the NIST RMF involves categorizing information systems based on the potential impact of a security breach?