CNDA Risk Management and Compliance 1 — Questions and Answers
Question 1: In risk management, what does the formula Risk = Threat × Vulnerability × Impact represent?
- A patch priority formula
- A qualitative method for calculating risk exposure based on threat likelihood, exploitability, and business impact (Correct answer)
- A compliance scoring model
- A firewall rule priority formula
Correct answer: A qualitative method for calculating risk exposure based on threat likelihood, exploitability, and business impact
This formula helps prioritize risks by combining the likelihood of a threat exploiting a vulnerability with the potential business impact.
Question 2: Which risk treatment option involves purchasing cyber insurance to offset potential financial losses?
- Risk avoidance
- Risk mitigation
- Risk transference (Correct answer)
- Risk acceptance
Correct answer: Risk transference
Risk transference shifts the financial impact of a risk to a third party, such as an insurance provider, without eliminating the risk itself.
Question 3: What US federal law requires federal agencies to implement a risk management framework for information security?
- HIPAA
- PCI-DSS
- FISMA (Federal Information Security Modernization Act) (Correct answer)
- SOX
Correct answer: FISMA (Federal Information Security Modernization Act)
FISMA requires federal agencies and contractors to develop, document, and implement information security programs based on NIST frameworks.
Question 4: In the NIST Risk Management Framework (RMF), what is the correct order of the first three steps?
- Assess, Select, Implement
- Categorize, Select, Implement
- Prepare, Categorize, Select (Correct answer)
- Select, Implement, Assess
Correct answer: Prepare, Categorize, Select
NIST RMF steps are: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor — Prepare was added in RMF Rev 2.
Question 5: Which compliance framework applies specifically to organizations that process, store, or transmit payment card data?
- HIPAA
- PCI-DSS (Correct answer)
- NIST CSF
- ISO 27001
Correct answer: PCI-DSS
PCI-DSS (Payment Card Industry Data Security Standard) is mandated by card brands for any entity handling cardholder data.
Question 6: A CNDA is performing a Business Impact Analysis (BIA). What are the two primary metrics gathered for each critical system?
- CVSS score and patch count
- RTO (Recovery Time Objective) and RPO (Recovery Point Objective) (Correct answer)
- Uptime percentage and bandwidth usage
- Number of users and storage capacity
Correct answer: RTO (Recovery Time Objective) and RPO (Recovery Point Objective)
RTO defines how quickly a system must be restored after failure, while RPO defines the maximum acceptable data loss measured in time.
In risk management, what does the formula Risk = Threat × Vulnerability × Impact represent?