CND Risk Management & Compliance 5 — Questions and Answers
Question 1: Which risk metric represents the expected loss from a single occurrence of a specific threat event?
- Annual Loss Expectancy (ALE)
- Annualized Rate of Occurrence (ARO)
- Single Loss Expectancy (SLE) (Correct answer)
- Exposure Factor (EF)
Correct answer: Single Loss Expectancy (SLE)
SLE = Asset Value × Exposure Factor, representing the dollar loss from one occurrence of a threat event against a specific asset.
Question 2: An organization implements multi-factor authentication to reduce the risk of credential theft. This is an example of which type of risk control?
- Corrective control
- Detective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Preventive controls are designed to stop security incidents before they occur; MFA prevents unauthorized access by requiring additional verification.
Question 3: Under GDPR, what is the maximum timeframe within which a data breach affecting EU citizens' rights must be reported to the supervisory authority?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires that data breaches likely to result in risk to individuals must be reported to the supervisory authority within 72 hours of discovery.
Question 4: In the context of risk management, a 'threat vector' refers to:
- The financial impact of a successfully exploited vulnerability
- The path or method used by a threat agent to exploit a vulnerability (Correct answer)
- The probability that a threat will occur within a year
- A list of all known vulnerabilities in a system
Correct answer: The path or method used by a threat agent to exploit a vulnerability
A threat vector is the specific route, method, or pathway through which a threat actor can exploit a vulnerability to cause harm.
Question 5: Which NIST SP 800-53 control family specifically addresses planning and policy for information security?
- Access Control (AC)
- Planning (PL) (Correct answer)
- Audit and Accountability (AU)
- Configuration Management (CM)
Correct answer: Planning (PL)
The Planning (PL) control family in NIST SP 800-53 covers security planning activities including system security plans and rules of behavior.
Question 6: A company outsources its payroll processing to a cloud provider. From a risk management perspective, what has the company primarily done?
- Avoided the risk entirely
- Accepted the residual risk
- Transferred a portion of the operational risk (Correct answer)
- Mitigated the risk through technical controls
Correct answer: Transferred a portion of the operational risk
Outsourcing transfers certain operational risks to the service provider, though the organization retains ultimate accountability for data protection.
Question 7: Which activity in a risk management program involves continuously tracking identified risks, monitoring residual risk, and identifying new risks over time?
- Risk assessment
- Risk identification
- Risk monitoring and review (Correct answer)
- Risk communication
Correct answer: Risk monitoring and review
Risk monitoring and review is an ongoing activity that ensures the risk management program remains current as the threat landscape and business environment change.
Which risk metric represents the expected loss from a single occurrence of a specific threat event?