CORES Technology & Cyber Risk Management 3 — Questions and Answers
Question 1: An operational risk manager is evaluating cyber risks using the FAIR (Factor Analysis of Information Risk) model. What are the two top-level factors FAIR decomposes risk into?
- Threat Event Frequency and Vulnerability
- Loss Event Frequency and Loss Magnitude (Correct answer)
- Inherent Risk and Residual Risk
- Control Effectiveness and Asset Value
Correct answer: Loss Event Frequency and Loss Magnitude
FAIR decomposes risk into Loss Event Frequency (how often a loss event occurs) and Loss Magnitude (how much loss results), enabling probabilistic financial quantification.
Question 2: Which regulatory framework requires US financial institutions to notify their primary federal regulator within 36 hours of a significant computer security incident?
- FFIEC Cybersecurity Assessment Tool (CAT)
- OCC Computer-Security Incident Notification Rule (Correct answer)
- NIST Cybersecurity Framework (CSF)
- GLBA Safeguards Rule
Correct answer: OCC Computer-Security Incident Notification Rule
The OCC/Federal Reserve/FDIC Computer-Security Incident Notification Rule requires banking organizations to notify their primary federal regulator within 36 hours of a significant incident.
Question 3: What is the key distinction between a vulnerability assessment and a penetration test in technology risk management?
- Vulnerability assessments are automated; penetration tests are always manual
- Vulnerability assessments identify weaknesses; penetration tests actively exploit them to demonstrate impact (Correct answer)
- Penetration tests use real attacker tools while vulnerability assessments use vendor tools only
- Vulnerability assessments require regulatory approval; penetration tests do not
Correct answer: Vulnerability assessments identify weaknesses; penetration tests actively exploit them to demonstrate impact
Vulnerability assessments scan and catalog weaknesses, while penetration tests go further by attempting to exploit those weaknesses to measure real-world risk impact.
Question 4: A CORES candidate is reviewing a firm's cyber risk appetite statement. Which element is MOST critical to include?
- A list of approved security vendors and their contract values
- Defined thresholds for tolerable cyber loss exposure aligned to business strategy (Correct answer)
- The complete inventory of all IT assets and their risk ratings
- The schedule for mandatory employee cybersecurity training
Correct answer: Defined thresholds for tolerable cyber loss exposure aligned to business strategy
A cyber risk appetite statement must articulate the level of risk the organization is willing to accept, expressed in measurable thresholds tied to strategic objectives.
Question 5: Which attack technique involves embedding malicious code in a legitimate website visited by targeted employees to deliver malware without direct interaction?
- Spear phishing
- Watering hole attack (Correct answer)
- SQL injection
- Man-in-the-middle attack
Correct answer: Watering hole attack
A watering hole attack compromises websites frequently visited by the target group, passively delivering malware when victims browse to the trusted but infected site.
Question 6: In business continuity planning for technology systems, what does RTO (Recovery Time Objective) define?
- The maximum amount of data that can be lost, measured in time
- The maximum acceptable time to restore a system or process after disruption (Correct answer)
- The frequency at which backups must be performed
- The percentage of systems that must remain available during a disaster
Correct answer: The maximum acceptable time to restore a system or process after disruption
RTO defines the maximum tolerable duration of downtime for a system or process before the disruption causes unacceptable business impact.
Question 7: What is the primary risk management benefit of network micro-segmentation in an enterprise IT environment?
- It reduces the total number of network devices requiring maintenance
- It limits lateral movement by attackers after an initial breach (Correct answer)
- It eliminates the need for endpoint detection and response (EDR) tools
- It ensures compliance with all applicable data privacy regulations
Correct answer: It limits lateral movement by attackers after an initial breach
Micro-segmentation divides networks into isolated zones so that a compromised segment cannot easily be used to pivot to other systems, limiting breach blast radius.
An operational risk manager is evaluating cyber risks using the FAIR (Factor Analysis of Information Risk) model.
What are the two top-level factors FAIR decomposes risk into?