CORES Technology & Cyber Risk Management 2 — Questions and Answers
Question 1: A bank's core banking system experiences a zero-day vulnerability exploited before a patch is available. What is the MOST appropriate immediate response?
- Shut down all banking operations until patched
- Apply compensating controls such as network segmentation and enhanced monitoring (Correct answer)
- Disclose the vulnerability publicly to get community help
- Wait for the vendor to release an official patch before taking action
Correct answer: Apply compensating controls such as network segmentation and enhanced monitoring
Compensating controls like network segmentation and enhanced monitoring reduce exposure while a formal patch is developed, balancing security with operational continuity.
Question 2: Under NIST SP 800-53, which control family specifically addresses incident response planning for IT systems?
- Access Control (AC)
- Incident Response (IR) (Correct answer)
- System and Communications Protection (SC)
- Audit and Accountability (AU)
Correct answer: Incident Response (IR)
The Incident Response (IR) control family in NIST SP 800-53 covers planning, testing, handling, and monitoring of security incidents.
Question 3: Which metric in a cyber risk quantification model best captures the financial impact of a ransomware event affecting production systems?
- Mean Time to Detect (MTTD)
- Annual Loss Expectancy (ALE) (Correct answer)
- Recovery Time Objective (RTO)
- Maximum Tolerable Downtime (MTD)
Correct answer: Annual Loss Expectancy (ALE)
Annual Loss Expectancy (ALE) combines the probability of a threat event with its single occurrence loss, providing a financial measure of cyber risk.
Question 4: A firm's third-party cloud provider suffers a breach exposing customer PII. Under operational risk management principles, who bears primary accountability?
- The cloud provider exclusively, as the data custodian
- The firm, because outsourcing activity does not transfer regulatory accountability (Correct answer)
- Regulators, as they set cloud usage standards
- Cyber insurers, since the policy covers third-party breaches
Correct answer: The firm, because outsourcing activity does not transfer regulatory accountability
Regulators and risk frameworks hold the firm accountable for risks arising from outsourced activities; the firm cannot transfer its compliance obligations.
Question 5: What is the primary purpose of a cyber tabletop exercise in an operational risk program?
- To identify and remediate all existing vulnerabilities
- To test response coordination and decision-making without real operational impact (Correct answer)
- To satisfy annual penetration testing requirements
- To generate evidence for regulatory reporting on cyber spend
Correct answer: To test response coordination and decision-making without real operational impact
Tabletop exercises simulate cyber scenarios in a discussion-based format to evaluate the effectiveness of incident response plans and team coordination.
Question 6: Which of the following BEST describes a supply chain attack in a technology risk context?
- A denial-of-service attack targeting logistics management software
- Compromising a trusted software vendor or hardware supplier to gain access to downstream customers (Correct answer)
- An insider threat exploiting procurement system credentials
- A ransomware attack that encrypts ERP systems used in supply chain management
Correct answer: Compromising a trusted software vendor or hardware supplier to gain access to downstream customers
Supply chain attacks exploit trusted relationships with vendors or suppliers to infiltrate multiple downstream organizations through a single compromise.
Question 7: In cyber risk governance, what does a 'heat map' typically illustrate?
- Geographic distribution of cyberattacks across the enterprise
- The relationship between likelihood and impact of identified cyber risks (Correct answer)
- Network traffic volume by time of day
- Employee phishing susceptibility rates by department
Correct answer: The relationship between likelihood and impact of identified cyber risks
A risk heat map plots risks on a two-dimensional grid of likelihood versus impact, enabling prioritization and executive communication of the risk landscape.
A bank's core banking system experiences a zero-day vulnerability exploited before a patch is available.
What is the MOST appropriate immediate response?